0.0

CVE-2026-30558 - Reflected XSS via msg Parameter in SourceCodester Sales and Inventory System 1.0

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_customer.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or H…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:56 p.m.

0.0

CVE-2026-33643 -

SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file plugins/mysql/lib/column.go.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:32 p.m.

0.0

CVE-2026-30306 -

In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be pote…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 9:17 p.m.

7.1

CVSS3.1

CVE-2026-34472 - Unauthenticated Access to ZTE ZXHN H188A Router Credentials

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including the default administrator password, WLAN PSK,…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:56 p.m.

9.3

CVSS3.1

CVE-2026-30562 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-30077 -

OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example input in hex stream is 80 00 00 0E 00 00 01 00 0F 80 02 02 40 00 58 00 01 88.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-29953 -

SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins/postgres/lib/column.go.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:16 p.m.

0.0

CVE-2026-29924 -

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 7:16 p.m.

0.0

CVE-2026-33373 - Cross‑Site Request Forgery Allowing Unauthorized Account State Changes in Zimbra Collaboration

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state transitions. Specifically, tokens generated after oper…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:56 p.m.

0.0

CVE-2026-30560 - Reflected XSS via msg Parameter in SourceCodester Sales and Inventory System 1.0

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_supplier.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or H…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:56 p.m.
Total resulsts: 341475
Page 40 of 34,148
Β« previous page Β» next page
Filters