5.1

CVSS4.0

CVE-2026-32843 - Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious U…

πŸ“… Published: March 19, 2026, 2:39 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

10

CVSS3.1

CVE-2026-22557 -

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

πŸ“… Published: March 19, 2026, 2:24 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

7.7

CVSS3.1

CVE-2026-22558 -

An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.

πŸ“… Published: March 19, 2026, 2:24 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

8.7

CVSS4.0

CVE-2025-71260 - BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter …

πŸ“… Published: March 19, 2026, 1:45 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.3

CVSS4.0

CVE-2025-71259 - BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficient validation of ext…

πŸ“… Published: March 19, 2026, 1:44 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.3

CVSS4.0

CVE-2025-71258 - BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perfo…

πŸ“… Published: March 19, 2026, 1:44 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

6.9

CVSS4.0

CVE-2025-71257 - BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can bypass access controls to invoke restricted functionality and…

πŸ“… Published: March 19, 2026, 1:43 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

8.6

CVSS3.1

CVE-2026-3511 -

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable applica…

πŸ“… Published: March 19, 2026, 11:25 a.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

7.5

CVSS3.1

CVE-2026-3658 - Appointment Booking Calendar <= 1.6.10.0 - Unauthenticated SQL Injection via 'fields' Parameter

The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in all versions up to, and including, 1.6.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

πŸ“… Published: March 19, 2026, 11:15 a.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

9.8

CVSS3.1

CVE-2006-10003 - XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the al…

πŸ“… Published: March 19, 2026, 11:08 a.m. πŸ”„ Last Modified: March 19, 2026, 6:41 p.m.
Total resulsts: 338974
Page 32 of 33,898
Β« previous page Β» next page
Filters