0.0

CVE-2026-31262 -

Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the URL parameter

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.

0.0

CVE-2026-23780 -

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitr…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.

3.5

CVSS3.1

CVE-2026-33551 - Privilege Escalation via Restricted Application Credentials in OpenStack Keystone

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role m…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 2:16 p.m.

0.0

CVE-2026-23782 -

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to una…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.

0.0

CVE-2026-36235 -

A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.

0.0

CVE-2026-29861 -

PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.

0.0

CVE-2026-36233 -

A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for appropri…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.

0.0

CVE-2026-36236 -

SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.

0.0

CVE-2026-36234 -

itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.

0.0

CVE-2026-36232 -

A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or validation.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.
Total resulsts: 343968
Page 29 of 34,397
Β« previous page Β» next page
Filters