0.0

CVE-2026-30556 - Reflected XSS in SourceCodester Sales and Inventory System via msg Parameter

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the index.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:56 p.m.

0.0

CVE-2026-30313 -

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate commands; while it intercepts dangerous operators such as ;, &&, ||, |, and co…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 9:17 p.m.

6.5

CVSS3.1

CVE-2026-29597 -

Incorrect access control in the file_details.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allows attackers with editor privileges to access sensitive files via crafted requests.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:16 p.m.

0.0

CVE-2026-29909 -

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:24 p.m.

0.0

CVE-2026-29925 -

Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:16 p.m.

0.0

CVE-2026-30559 - Reflected XSS via msg Parameter in SourceCodester Sales and Inventory System 1.0

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_sales.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:56 p.m.

0.0

CVE-2026-30561 - Reflected XSS in SourceCodester Sales and Inventory System 1.0

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_purchase.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or H…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:56 p.m.

0.0

CVE-2026-30307 -

Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it …

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:05 p.m.

0.0

CVE-2026-30305 -

Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fai…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:39 p.m.

7.6

CVSS3.1

CVE-2026-29954 -

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address. More critically, when kubeconfiggenerator uses wget to down…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:16 p.m.
Total resulsts: 341475
Page 39 of 34,148
Β« previous page Β» next page
Filters