2.7

CVSS3.1

CVE-2026-36922 -

Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 5:43 p.m.

2.7

CVSS3.1

CVE-2026-36874 - SQL Injection in Basic Library System Load Student Script

Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 3:45 p.m.

0.0

CVE-2026-29955 - KubePlus 4.14 Command Injection via /registercrd Endpoint

The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` parameter to execute shell commands, and the user-supplied `chartName` parameter is directly concatenated into the command …

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 3:29 p.m.

2.7

CVSS3.1

CVE-2026-36952 - SQL Injection in Sourcecodester Online Thesis Archiving System

Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:35 p.m.

0.0

CVE-2026-31048 - Arbitrary Code Execution via Pickle Deserialization in Pyro v3.x

An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 3:31 p.m.

7.5

CVSS3.1

CVE-2026-30997 - FFmpeg: FFmpeg: Denial of Service via out-of-bounds read

An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 8:16 p.m.

5.4

CVSS3.1

CVE-2025-70936 - Reflected XSS in Vtiger CRM 8.4.0 MailManager via Double URL‑Encoded Folder Parameter

Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and executed in the context of an authenticated user s…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:35 p.m.

2.7

CVSS3.1

CVE-2026-36873 -

Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 5:42 p.m.

5.5

CVSS3.1

CVE-2026-31424 - netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP Weiming Shi says: xt_match and xt_target structs registered with NFPROTO_UNSPEC can be loaded by any protocol family through nft_compat. Whe…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 3:01 p.m.

0.0

CVE-2026-31418 - netfilter: ipset: drop logically empty buckets in mtype_del

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in mtype_del mtype_del() counts empty slots below n->pos in k, but it only drops the bucket when both n->pos and k are zero. This misses buckets whose live entries have all been remo…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 3:01 p.m.
Total resulsts: 344718
Page 69 of 34,472
Β« previous page Β» next page
Filters