7.1

CVSS3.1

CVE-2026-42261 - PromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`

PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills.ts exposes an authenticated endpoint POST /api/skills/fetch-remote that fetches a user-supplied URL server-side and reflects the response body (up to…

📅 Published: May 8, 2026, 3:11 a.m. 🔄 Last Modified: May 8, 2026, 3:11 a.m.

9.4

CVSS4.0

CVE-2026-43944 - electerm: dangerous code can be run through links or command line

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or openi…

📅 Published: May 8, 2026, 3:08 a.m. 🔄 Last Modified: May 8, 2026, 3:08 a.m.

5.5

CVSS3.1

CVE-2026-43942 - electerm: Full process.env exposed to renderer via window.pre.env in electerm

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as window.pre.env and is access…

📅 Published: May 8, 2026, 3:03 a.m. 🔄 Last Modified: May 8, 2026, 3:03 a.m.

9.6

CVSS3.1

CVE-2026-43941 - Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link cl…

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal outp…

📅 Published: May 8, 2026, 3:01 a.m. 🔄 Last Modified: May 8, 2026, 3:01 a.m.

6.9

CVSS4.0

CVE-2026-8131 - SourceCodester SUP Online Shopping replymsg.php sql injection

A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The manipulation of the argument msgid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public…

📅 Published: May 8, 2026, 3 a.m. 🔄 Last Modified: May 8, 2026, 3 a.m.

8.4

CVSS3.1

CVE-2026-43940 - electerm: Path traversal in electerm runWidget leads to arbitrary code execution

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating user‑supplied widget identifiers without any sanitisation. Because runWidget i…

📅 Published: May 8, 2026, 2:58 a.m. 🔄 Last Modified: May 8, 2026, 12:52 p.m.

7.8

CVSS3.1

CVE-2026-43943 - electerm: RCE via malicious SSH server filename in openFileWithEditor

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code execution (RCE) vulnerability exists in electerm's SFTP open with system editor or "Edit with custom editor" feature. When a user opts to edit a file using open with system edito…

📅 Published: May 8, 2026, 2:55 a.m. 🔄 Last Modified: May 8, 2026, 2:55 a.m.

9.8

CVSS3.1

CVE-2026-41500 - electerm has Command Injection Vulnerability via runMac function

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:150. The runMac() function appends attacker-controlled remote releaseInfo.name directly into an ex…

📅 Published: May 8, 2026, 2:53 a.m. 🔄 Last Modified: May 8, 2026, 2:53 a.m.

9.8

CVSS3.1

CVE-2026-41501 - electerm has Command Injection Vulnerability via runLinux function

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:130. The runLinux() function appends attacker-controlled remote version strings directly into an e…

📅 Published: May 8, 2026, 2:51 a.m. 🔄 Last Modified: May 8, 2026, 11:19 a.m.

6.9

CVSS4.0

CVE-2026-8130 - SourceCodester SUP Online Shopping message.php sql injection

A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipulation of the argument seenid leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be u…

📅 Published: May 8, 2026, 2:45 a.m. 🔄 Last Modified: May 8, 2026, 2:45 a.m.
Total resulsts: 349182
Page 31 of 34,919
« previous page » next page
Filters