4.8

CVSS4.0

CVE-2026-5602 - Nor2-io heim-mcp new_heim_application tools.ts registerTools os command injection

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local ac…

πŸ“… Published: April 5, 2026, 10:15 p.m. πŸ”„ Last Modified: April 5, 2026, 11:16 p.m.

8.1

CVSS3.1

CVE-2026-4272 - CVE-2026-4272 - Bluetooth Remote Execution of System Commands Vulnerability

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK000…

πŸ“… Published: April 5, 2026, 10 p.m. πŸ”„ Last Modified: April 5, 2026, 10 p.m.

6.9

CVSS4.0

CVE-2026-5601 - Acrel Electrical Prepaid Cloud Platform Backup File bin.rar information disclosure

A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public a…

πŸ“… Published: April 5, 2026, 10 p.m. πŸ”„ Last Modified: April 7, 2026, 2:56 a.m.

3.5

CVSS3.1

CVE-2026-35679 - Potential Sprout Pool Funds Drainage via Accepting Invalid Transactions

Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.

πŸ“… Published: April 5, 2026, 9:26 p.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5597 - griptape-ai griptape ComputerTool tool.py path traversal

A flaw has been found in griptape-ai griptape 0.19.4. This affects an unknown part of the file griptape\tools\computer\tool.py of the component ComputerTool. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has b…

πŸ“… Published: April 5, 2026, 9:15 p.m. πŸ”„ Last Modified: April 5, 2026, 9:15 p.m.

8.8

CVSS4.0

CVE-2019-25675 - eDirectory All Versions SQL Injection Authentication Bypass

eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to …

πŸ“… Published: April 5, 2026, 8:58 p.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

8.8

CVSS4.0

CVE-2019-25704 - Kados R10 GreenBee SQL Injection via filter_user_mail

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. Attackers can send crafted requests with malicious SQL statements to extract sensitive database information or modify data.

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 7, 2026, 7:36 p.m.

8.8

CVSS4.0

CVE-2019-25702 - Kados R10 GreenBee SQL Injection via id_project Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database informa…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 7, 2026, 7:37 p.m.

8.8

CVSS4.0

CVE-2019-25700 - Kados R10 GreenBee SQL Injection via sort_direction Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL statements in the sort_direction parameter to extract sensitive database information or modi…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 7, 2026, 7:37 p.m.

8.8

CVSS4.0

CVE-2019-25698 - Kados R10 GreenBee SQL Injection via id_to_delete Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive databa…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 7, 2026, 7:37 p.m.
Total resulsts: 343040
Page 68 of 34,304
Β« previous page Β» next page
Filters