4.6

CVSS3.1

CVE-2026-33193 - Docmost vulnerable to stored XSS via MIME type spoofing

Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of MIME type spoofing (GHSL-2026-052). An attacker could exploit this flaw to inject malicious scripts, potentially co…

πŸ“… Published: April 14, 2026, 9:39 p.m. πŸ”„ Last Modified: April 16, 2026, 1:51 p.m.

8.8

CVSS3.1

CVE-2026-40291 - Chamilo LMS has Privilege Escalation via API User Role Modification

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in the PUT /api/users/{id} endpoint allows any authenticated user with ROLE_STUDENT to escalate their privileges to ROLE_ADMIN by modifying the roles field…

πŸ“… Published: April 14, 2026, 9:37 p.m. πŸ”„ Last Modified: April 14, 2026, 10:16 p.m.

4.3

CVSS3.1

CVE-2026-33146 - Docmost's Public Share Search Exposes Metadata of Restricted Children

Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets through the public search endpoint (`POST /api/search/share-search`) for publicly shared content. This…

πŸ“… Published: April 14, 2026, 9:36 p.m. πŸ”„ Last Modified: April 14, 2026, 10:16 p.m.

8.8

CVSS3.1

CVE-2026-35196 - Chamilo LMS has OS Command Injection via export_all_certificates action

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates action, where the course code retrieved from the session variable $_SESSION['_c…

πŸ“… Published: April 14, 2026, 9:33 p.m. πŸ”„ Last Modified: April 14, 2026, 10:16 p.m.

7.1

CVSS3.1

CVE-2026-34602 - Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into C…

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object Reference (IDOR), allowing an authenticated attacker to modify the user parameter in the request body to enroll any arbitrary user in…

πŸ“… Published: April 14, 2026, 9:29 p.m. πŸ”„ Last Modified: April 15, 2026, 1:32 p.m.

5.3

CVSS3.1

CVE-2025-15565 - Nexi XPay <= 8.3.0 - Missing Authorization to Unauthenticated Order Status Modification

The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed.

πŸ“… Published: April 14, 2026, 9:26 p.m. πŸ”„ Last Modified: April 15, 2026, 1:33 p.m.

6.5

CVSS3.1

CVE-2026-34370 - Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated student to read the private course notes of any other user on the platform by manipulating t…

πŸ“… Published: April 14, 2026, 9:25 p.m. πŸ”„ Last Modified: April 15, 2026, 8:03 p.m.

7

CVSS4.0

CVE-2026-39907 - Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via WCF SOAP

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak NTLMv2 machine-accoun…

πŸ“… Published: April 14, 2026, 9:21 p.m. πŸ”„ Last Modified: April 14, 2026, 10:16 p.m.

7

CVSS4.0

CVE-2026-39906 - Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via .NET Remoting

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques…

πŸ“… Published: April 14, 2026, 9:21 p.m. πŸ”„ Last Modified: April 16, 2026, 1:50 p.m.

7.8

CVSS3.1

CVE-2026-34631 - InCopy | Out-of-bounds Write (CWE-787)

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: April 14, 2026, 9:14 p.m. πŸ”„ Last Modified: April 15, 2026, 7:33 p.m.
Total resulsts: 344963
Page 41 of 34,497
Β« previous page Β» next page
Filters