6.1

CVSS3.1

CVE-2026-40565 - FreeScout has Stored XSS / CSS Injection via linkify() β€” Unescaped URL in Anchor href

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php converts plain-text URLs in email bodies into HTML anchor tags without escaping double-quote characters (") in the URL. HTMLPurifier (called first via getCle…

πŸ“… Published: April 21, 2026, 3:52 p.m. πŸ”„ Last Modified: April 22, 2026, 5:34 p.m.

10

CVSS3.1

CVE-2025-15638 - Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.

πŸ“… Published: April 21, 2026, 3:34 p.m. πŸ”„ Last Modified: April 22, 2026, 5:35 p.m.

10

CVSS3.1

CVE-2017-20230 - Storable versions before 3.05 for Perl has a stack overflow

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

πŸ“… Published: April 21, 2026, 3:26 p.m. πŸ”„ Last Modified: April 22, 2026, 5:36 p.m.

5.1

CVSS4.0

CVE-2025-41011 - HTML injection in PHP Point Of Sale

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' …

πŸ“… Published: April 21, 2026, 3:15 p.m. πŸ”„ Last Modified: April 22, 2026, 11:46 a.m.

8.9

CVSS4.0

CVE-2026-40498 - FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APP_KEY, which is exposed in…

πŸ“… Published: April 21, 2026, 3:01 p.m. πŸ”„ Last Modified: April 22, 2026, 5:34 p.m.

9.3

CVSS4.0

CVE-2025-41029 - SQL injection in Zeon Academy Pro by Zeon Global Tech

SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameter 'phonenumber' in '/private/continue-upload.php'.

πŸ“… Published: April 21, 2026, 2:59 p.m. πŸ”„ Last Modified: April 22, 2026, 11:46 a.m.

8.8

CVSS4.0

CVE-2026-3298 - Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes

The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.

πŸ“… Published: April 21, 2026, 2:45 p.m. πŸ”„ Last Modified: April 21, 2026, 11 p.m.

5.1

CVSS4.0

CVE-2025-10354 - Reflected Cross-Site Scripting (XSS) in Semantic MediaWiki

Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploit…

πŸ“… Published: April 21, 2026, 2:42 p.m. πŸ”„ Last Modified: April 21, 2026, 11 p.m.

5.3

CVSS3.1

CVE-2025-31981 - HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.Β  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

πŸ“… Published: April 21, 2026, 2:26 p.m. πŸ”„ Last Modified: April 22, 2026, 3:09 p.m.

8.5

CVSS4.0

CVE-2026-5789 - Search path without quotes in CivetWeb

Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb…

πŸ“… Published: April 21, 2026, 2:22 p.m. πŸ”„ Last Modified: April 22, 2026, 11:46 a.m.
Total resulsts: 346087
Page 62 of 34,609
Β« previous page Β» next page
Filters