9.6

CVSS3.1

CVE-2025-15036 - Path Traversal Vulnerability in mlflow/mlflow

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extracti…

📅 Published: March 30, 2026, 1:16 a.m. 🔄 Last Modified: March 31, 2026, 8 p.m.

5.3

CVSS4.0

CVE-2026-5103 - Totolink A3300R cstecgi.cgi setUPnPCfg command injection

A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection. The attack is possible to be carried out remotely. The exploit has been made avai…

📅 Published: March 30, 2026, 1 a.m. 🔄 Last Modified: March 30, 2026, 8:56 p.m.

2.1

CVSS4.0

CVE-2025-7741 -

Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the PROG user. The default …

📅 Published: March 30, 2026, 12:01 a.m. 🔄 Last Modified: March 30, 2026, 1:26 p.m.

5.3

CVSS4.0

CVE-2026-5102 - Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection

A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be execu…

📅 Published: March 30, 2026, midnight 🔄 Last Modified: March 30, 2026, 8:56 p.m.

6.1

CVSS3.1

CVE-2026-30565 - Reflected Cross‑Site Scripting via 'limit' Parameter in View Supplier

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script o…

📅 Published: March 30, 2026, midnight 🔄 Last Modified: March 30, 2026, 8:56 p.m.

6.1

CVSS3.1

CVE-2026-30564 - Reflected XSS via Unsanitized 'limit' Parameter in SourceCodester Sales and Inventory System 1.0

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script o…

📅 Published: March 30, 2026, midnight 🔄 Last Modified: March 30, 2026, 8:56 p.m.

0.0

CVE-2026-30308 -

In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a c…

📅 Published: March 30, 2026, midnight 🔄 Last Modified: March 30, 2026, 9:17 p.m.

6.1

CVSS3.1

CVE-2026-30082 - Stored Cross‑Site Scripting in IngEstate Server Software Package List Edit Feature

Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters.

📅 Published: March 30, 2026, midnight 🔄 Last Modified: March 30, 2026, 8:56 p.m.

6.1

CVSS3.1

CVE-2026-30566 - Reflected XSS in view_customers.php via 'limit' Parameter

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script …

📅 Published: March 30, 2026, midnight 🔄 Last Modified: March 30, 2026, 8:56 p.m.

6.1

CVSS3.1

CVE-2026-30563 - Stored XSS in SourceCodester Sales and Inventory System via Unsanitized Website Field

A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update_details.php file. The application fails to sanitize the "website" parameter provided in a POST request. This allows authenticated attackers to inject…

📅 Published: March 30, 2026, midnight 🔄 Last Modified: March 30, 2026, 8:56 p.m.
Total resulsts: 341527
Page 43 of 34,153
« previous page » next page
Filters