4.6

CVSS3.1

CVE-2026-39417 - MaxKB: RCE via MCP stdio command injection in workflow engine

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execution vulnerability still exists in the MCP node of the workflow engine. MaxKB only restricts the referencing code path (loading MCP config from the da…

πŸ“… Published: April 14, 2026, 12:03 a.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

2.7

CVSS3.1

CVE-2026-37601 -

SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:32 p.m.

2.7

CVSS3.1

CVE-2026-37592 -

Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:32 p.m.

2.7

CVSS3.1

CVE-2026-37589 -

SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:25 p.m.

8.5

CVSS3.1

CVE-2026-38527 - Server-Side Request Forgery in Webkul Krayin CRM Webhooks Endpoint Enables Internal Network Discove…

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

9.9

CVSS3.1

CVE-2026-38526 - Authenticated Arbitrary File Upload Allowing Remote Code Execution in Webkul Krayin CRM v2.2.x

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

2.7

CVSS3.1

CVE-2026-37600 -

SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:32 p.m.

2.7

CVSS3.1

CVE-2026-37593 -

SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:32 p.m.

9.8

CVSS3.1

CVE-2025-63939 - SQL Injection in Grocery Store Management System via search_products_itname.php

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

9.8

CVSS3.1

CVE-2025-70023 -

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 346903
Page 264 of 34,691
Β« previous page Β» next page
Filters