6.9

CVSS4.0

CVE-2026-7702 - toeverything AFFiNE Public Markdown Preview Endpoint :docId allowDocPreview authorization

A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId/:docId of the component Public Markdown Preview Endpoint. The manipulation results in authorization bypass. It is possible to launch the attack remotโ€ฆ

๐Ÿ“… Published: May 3, 2026, 3:45 p.m. ๐Ÿ”„ Last Modified: May 3, 2026, 3:45 p.m.

5.3

CVSS4.0

CVE-2026-7701 - Telegram Desktop Bot API url_auth_box.cpp RequestButton null pointer dereference

A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is posโ€ฆ

๐Ÿ“… Published: May 3, 2026, 3:30 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 4:06 p.m.

5.3

CVSS4.0

CVE-2026-7700 - langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection

A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p of the component LambdaFilterComponent. Executing a manipulation can lead to code injection. The attack may be performed from remoโ€ฆ

๐Ÿ“… Published: May 3, 2026, 2:15 p.m. ๐Ÿ”„ Last Modified: May 5, 2026, 12:43 a.m.

5.3

CVSS4.0

CVE-2026-7699 - Dromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injection

A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file StrUtils.java. Performing a manipulation of the argument filtersfields results in sql injection. The attack is possible to be carried out remotely. The eโ€ฆ

๐Ÿ“… Published: May 3, 2026, 2 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 1:21 p.m.

6.9

CVSS4.0

CVE-2026-7698 - Tiandy Easy7 Integrated Management Platform updateDbBackupInfo os command injection

A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo/updateDbBackupInfo. Such manipulation of the argument week leads to os command injection. The attack can be executed reโ€ฆ

๐Ÿ“… Published: May 3, 2026, 1:30 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 1:03 p.m.

5.1

CVSS4.0

CVE-2026-7697 - AMTT Hotel Broadband Operation System cardhand_submit.php sql injection

A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected is an unknown function of the file /manager/card/cardhand_submit.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosโ€ฆ

๐Ÿ“… Published: May 3, 2026, 1:15 p.m. ๐Ÿ”„ Last Modified: May 3, 2026, 9 p.m.

5.3

CVSS4.0

CVE-2026-7696 - Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform uploadH5Files unresโ€ฆ

A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remoโ€ฆ

๐Ÿ“… Published: May 3, 2026, 12:30 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 4:06 p.m.

6.9

CVSS4.0

CVE-2026-7695 - Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform elecMaxMinAvgValue โ€ฆ

A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initโ€ฆ

๐Ÿ“… Published: May 3, 2026, 12:15 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 4:06 p.m.

6.9

CVSS4.0

CVE-2026-7694 - Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue โ€ฆ

A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impacted element is an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. Executing a manipulation of the argument fCircuitids can lead to sql injection. The attacโ€ฆ

๐Ÿ“… Published: May 3, 2026, 11:45 a.m. ๐Ÿ”„ Last Modified: May 5, 2026, 12:42 a.m.

5.3

CVSS4.0

CVE-2026-7692 - Wavlink WL-WN570HA1 adm.cgi ping_ddns command injection

A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS results in command injection. The attack can be initiated remotely. The exploit is now public and may โ€ฆ

๐Ÿ“… Published: May 3, 2026, 11 a.m. ๐Ÿ”„ Last Modified: May 4, 2026, 1:21 p.m.
Total resulsts: 348413
Page 68 of 34,842
ยซ previous page ยป next page
Filters