6.5

CVSS3.1

CVE-2026-32120 - OpenEMR has IDOR in Fee Sheet Product Save

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (`library/FeeSheet.class.php`) allows any authenticated user with fee sheetโ€ฆ

๐Ÿ“… Published: March 25, 2026, 10:27 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 6:03 p.m.

8.1

CVSS3.1

CVE-2026-29187 - OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality (/interface/new/new_search_popup.php). The vulnerability allows an authenticated attackerโ€ฆ

๐Ÿ“… Published: March 25, 2026, 10:24 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 7:52 p.m.

7.3

CVSS4.0

CVE-2026-4824 - Enter Software Iperius Backup Backup Job Configuration File privileges management

A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Backup Job Configuration File Handler. The manipulation leads to improper privilege management. The attack must be carried out locally. The attack is coโ€ฆ

๐Ÿ“… Published: March 25, 2026, 9:44 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:31 a.m.

2

CVSS4.0

CVE-2026-4823 - Enter Software Iperius Backup NTLM2 information disclosure

A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to information disclosure. The attack is restricted to local execution. Attacks of this nature are highly โ€ฆ

๐Ÿ“… Published: March 25, 2026, 9:44 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:31 a.m.

4.4

CVSS3.1

CVE-2025-36187 - Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge

IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.

๐Ÿ“… Published: March 25, 2026, 9:26 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:31 a.m.

4

CVSS3.1

CVE-2025-14684 - IBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to .

IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

๐Ÿ“… Published: March 25, 2026, 9:22 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:31 a.m.

8.6

CVSS3.1

CVE-2026-30976 - Sonarr Path Traversal vulnerability

Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windowsโ€ฆ

๐Ÿ“… Published: March 25, 2026, 9:11 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 5:53 p.m.

8.1

CVSS3.1

CVE-2026-30975 - Sonarr Authentication Bypass vulnerability

Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: `Disabled for Local Addresses`) without a reverse proxy running in front of Sonarr tโ€ฆ

๐Ÿ“… Published: March 25, 2026, 9:08 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:31 a.m.

6.5

CVSS3.1

CVE-2025-14807 - IBM InfoSphere Information Server is vulnerable to HTTP header injection

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOSTย headers. This could allow an attacker to conduct various attacks against the vulnerable system,ย including cross-site scripting, cache poisoning or sโ€ฆ

๐Ÿ“… Published: March 25, 2026, 8:46 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 6:23 p.m.

5.4

CVSS3.1

CVE-2026-1015 - IBM InfoSphere Information Server is vulnerable to server-side request forgery

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

๐Ÿ“… Published: March 25, 2026, 8:41 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 6:14 p.m.
Total resulsts: 340707
Page 29 of 34,071
ยซ previous page ยป next page
Filters