6.9

CVSS4.0

CVE-2026-5829 - code-projects Simple IT Discussion Forum content.php sql injection

A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly di…

πŸ“… Published: April 9, 2026, 1:15 a.m. πŸ”„ Last Modified: April 9, 2026, 4:16 p.m.

6.9

CVSS4.0

CVE-2026-5828 - code-projects Simple IT Discussion Forum addcomment.php sql injection

A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and c…

πŸ“… Published: April 9, 2026, 1 a.m. πŸ”„ Last Modified: April 9, 2026, 1 a.m.

6.9

CVSS4.0

CVE-2026-5827 - code-projects Simple IT Discussion Forum question-function.php sql injection

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…

πŸ“… Published: April 9, 2026, 12:45 a.m. πŸ”„ Last Modified: April 9, 2026, 12:45 a.m.

5.3

CVSS4.0

CVE-2026-5826 - code-projects Simple IT Discussion Forum edit-category.php cross site scripting

A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. The exploit has been published a…

πŸ“… Published: April 9, 2026, 12:30 a.m. πŸ”„ Last Modified: April 9, 2026, 1:56 p.m.

5.3

CVSS4.0

CVE-2026-5825 - code-projects Simple Laundry System delmemberinfo.php cross site scripting

A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /delmemberinfo.php. Performing a manipulation of the argument userid results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may …

πŸ“… Published: April 9, 2026, 12:15 a.m. πŸ”„ Last Modified: April 9, 2026, 2:55 p.m.

0.0

CVE-2025-70797 -

Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters.

πŸ“… Published: April 9, 2026, midnight πŸ”„ Last Modified: April 9, 2026, 9:21 p.m.

5.4

CVSS3.1

CVE-2025-70365 - Stored XSS in Kiamo Admin Interfaces

A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-supplied input in administrative interfaces. An authenticated administrative user can inject arbitrary JavaScript code that is executed in the browser of users viewing the affected p…

πŸ“… Published: April 9, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 6:16 p.m.

6.1

CVSS3.1

CVE-2025-63238 - Reflected XSS via gid parameter in LimeSurvey QuestionCreate

A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInstance() function in application/models/QuestionCreate.php. This allows an attacker to craft a malicious URL and compromise the logged in user.

πŸ“… Published: April 9, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 6:16 p.m.

0.0

CVE-2026-29923 -

The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged users to map arbitrary physical memory into their address space and modify critical kernel structures.

πŸ“… Published: April 9, 2026, midnight πŸ”„ Last Modified: April 9, 2026, 7:25 p.m.

0.0

CVE-2026-30478 -

A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted executable.

πŸ“… Published: April 9, 2026, midnight πŸ”„ Last Modified: April 9, 2026, 8:17 p.m.
Total resulsts: 344089
Page 68 of 34,409
Β« previous page Β» next page
Filters