9.3

CVSS4.0

CVE-2026-40620 - SenseLive X3050 Missing authentication for critical function

A vulnerability inย SenseLiveย X3050โ€™s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted moโ€ฆ

๐Ÿ“… Published: April 24, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 12:02 a.m.

8.4

CVSS4.0

CVE-2026-27841 - SenseLive X3050 Cross-Site request forgery

A vulnerability inย SenseLiveย X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Because the application does not enforce server-side validation of request origin or implement CSRF tokens, a malicious externโ€ฆ

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, 6:18 p.m.

4.4

CVSS3.1

CVE-2026-29051 - melange has Path Traversal via .PKGINFO in --persist-lint-results

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `melange build --persist-lint-results`) constructs output file paths by joining `--out-dir` with the `aโ€ฆ

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, midnight

6.1

CVSS3.1

CVE-2025-61872 -

Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter.

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, 4:16 p.m.

0.0

CVE-2026-31050 -

Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, 3:22 p.m.

0.0

CVE-2025-67259 -

A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized course-level information by modifying intercepted API requests. Changing a captured POST request to a GET request against the /rest/v1/course PostgREST enโ€ฆ

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, 4:16 p.m.

0.0

CVE-2026-31051 -

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, 3:57 p.m.

5.3

CVSS3.1

CVE-2026-31052 -

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout Authentication Flow component

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, 4:03 p.m.

0.0

CVE-2026-30368 -

A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, 3:31 p.m.

4

CVSS3.1

CVE-2026-42095 -

bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.

๐Ÿ“… Published: April 24, 2026, midnight ๐Ÿ”„ Last Modified: April 24, 2026, 5:55 p.m.
Total resulsts: 346529
Page 29 of 34,653
ยซ previous page ยป next page
Filters