5.3

CVSS4.0

CVE-2026-6487 - Qihui jtbc5 CMS Code Endpoint manage.php path traversal

A flaw has been found in Qihui jtbc5 CMS 5.0.3.6. Affected is an unknown function of the file /dev/code/common/diplomat/manage.php of the component Code Endpoint. This manipulation of the argument path causes path traversal. The attack is possible to be carried out remotely. The exploit has been pu…

πŸ“… Published: April 17, 2026, 12:30 p.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.1

CVSS4.0

CVE-2026-6486 - classroombookings User Display Name layout.php read cross site scripting

A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack can be executed remo…

πŸ“… Published: April 17, 2026, 12:15 p.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

4.3

CVSS3.1

CVE-2026-23777 - Remote Access Sensitive Information Exposure in Dell PowerProtect Data Domain

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an exposure of sensitive information to an unauthorized actor vulne…

πŸ“… Published: April 17, 2026, 11:52 a.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

5.9

CVSS3.1

CVE-2026-28263 - Cross‑Site Scripting in Dell PowerProtect Data Domain DD OS

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a cross-site Scripting vulnerability. A high privileged attacker wi…

πŸ“… Published: April 17, 2026, 11:44 a.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

7.5

CVSS3.1

CVE-2026-6507 - Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq d…

πŸ“… Published: April 17, 2026, 11:37 a.m. πŸ”„ Last Modified: April 20, 2026, 2:59 p.m.

6.2

CVSS3.1

CVE-2025-46606 - Improper Restriction of Excessive Authentication Attempts in Dell PowerProtect Data Domain OS

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading…

πŸ“… Published: April 17, 2026, 11:36 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 p.m.

6.2

CVSS3.1

CVE-2025-46605 - Session Fixation Vulnerability in Dell PowerProtect Data Domain

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

πŸ“… Published: April 17, 2026, 11:27 a.m. πŸ”„ Last Modified: April 20, 2026, 2:06 p.m.

6.6

CVSS3.1

CVE-2025-46641 - Improper Authentication in Dell PowerProtect Data Domain 8.4-8.5

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

πŸ“… Published: April 17, 2026, 11:19 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 p.m.

6.6

CVSS3.1

CVE-2025-46607 - Improper Authentication in Dell PowerProtect Data Domain Allowing Unauthorized Remote Access

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

πŸ“… Published: April 17, 2026, 11:13 a.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

6.7

CVSS3.1

CVE-2026-35073 - OS Command Injection Vulnerability in Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command injection vulnerability. A high privileged attacker wi…

πŸ“… Published: April 17, 2026, 11:05 a.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.
Total resulsts: 347814
Page 278 of 34,782
Β« previous page Β» next page
Filters