5.3

CVSS4.0

CVE-2026-32867 - OPEXUS eComplaint unauthenticated file upload

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users would see these unexpected files in cases. Uploading a large number of files could consume storage.

πŸ“… Published: March 19, 2026, 3:48 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-32866 - OPEXUS eComplaint and eCase stored XSS via profile first and last name

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a user profile. An authenticated attacker can inject parts of an XSS payload in their first and last name fields. The payload is executed when the user's full name is rendered. The at…

πŸ“… Published: March 19, 2026, 3:48 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

9.2

CVSS4.0

CVE-2026-32865 - OPEXUS eComplaint and eCase insecure password reset

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing securit…

πŸ“… Published: March 19, 2026, 3:47 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

7.2

CVSS3.1

CVE-2026-27043 - WordPress Photography theme <= 7.7.5 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/a through 7.7.5.

πŸ“… Published: March 19, 2026, 2:49 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-32843 - Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious U…

πŸ“… Published: March 19, 2026, 2:39 p.m. πŸ”„ Last Modified: March 20, 2026, 6:11 p.m.

10

CVSS3.1

CVE-2026-22557 -

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

πŸ“… Published: March 19, 2026, 2:24 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

7.7

CVSS3.1

CVE-2026-22558 -

An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.

πŸ“… Published: March 19, 2026, 2:24 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

8.7

CVSS4.0

CVE-2025-71260 - BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter …

πŸ“… Published: March 19, 2026, 1:45 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.3

CVSS4.0

CVE-2025-71259 - BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficient validation of ext…

πŸ“… Published: March 19, 2026, 1:44 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.3

CVSS4.0

CVE-2025-71258 - BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perfo…

πŸ“… Published: March 19, 2026, 1:44 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.
Total resulsts: 339064
Page 40 of 33,907
Β« previous page Β» next page
Filters