7.1

CVSS4.0

CVE-2026-33714 - Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)

Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint, which is an incomplete fix for CVE-2026-30881. While CVE-2026-30881 was patched by applying Security::remove_XSS() to the date_start and date_end pa…

πŸ“… Published: April 14, 2026, 9 p.m. πŸ”„ Last Modified: April 15, 2026, 8:03 p.m.

7.8

CVSS3.1

CVE-2026-27287 - InCopy | Out-of-bounds Read (CWE-125)

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exp…

πŸ“… Published: April 14, 2026, 8:54 p.m. πŸ”„ Last Modified: April 15, 2026, 3:58 a.m.

4.8

CVSS4.0

CVE-2026-25133 - October CMS has Stored XSS via SVG Filter Bypass

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler attributes (such as onclick or onload) could be bypassed using a …

πŸ“… Published: April 14, 2026, 8:47 p.m. πŸ”„ Last Modified: April 16, 2026, 1:47 p.m.

4.9

CVSS3.1

CVE-2026-25125 - October CMS: Environment Variable Exfiltration via INI Parser Interpolation

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attackers w…

πŸ“… Published: April 14, 2026, 8:39 p.m. πŸ”„ Last Modified: April 14, 2026, 9:16 p.m.

8.8

CVSS3.1

CVE-2026-24893 - openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address…

openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the …

πŸ“… Published: April 14, 2026, 8:37 p.m. πŸ”„ Last Modified: April 15, 2026, 1:40 p.m.

7.7

CVSS3.1

CVE-2026-40683 - OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handl…

In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_…

πŸ“… Published: April 14, 2026, 8:05 p.m. πŸ”„ Last Modified: April 15, 2026, 2:41 p.m.

7.8

CVSS3.1

CVE-2026-34630 - Bridge | Heap-based Buffer Overflow (CWE-122)

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: April 14, 2026, 7:53 p.m. πŸ”„ Last Modified: April 15, 2026, 3:59 a.m.

7.8

CVSS3.1

CVE-2026-27312 - Bridge | Heap-based Buffer Overflow (CWE-122)

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: April 14, 2026, 7:44 p.m. πŸ”„ Last Modified: April 15, 2026, 7:59 p.m.

5.5

CVSS3.1

CVE-2026-27222 - Bridge | Divide By Zero (CWE-369)

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a…

πŸ“… Published: April 14, 2026, 7:44 p.m. πŸ”„ Last Modified: April 15, 2026, 7:59 p.m.

7.8

CVSS3.1

CVE-2026-27310 - Bridge | Heap-based Buffer Overflow (CWE-122)

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: April 14, 2026, 7:44 p.m. πŸ”„ Last Modified: April 15, 2026, 7:59 p.m.
Total resulsts: 344980
Page 44 of 34,498
Β« previous page Β» next page
Filters