6.9

CVSS4.0

CVE-2026-5198 - code-projects Student Membership System Admin Login index.php sql injection

A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possib…

πŸ“… Published: March 31, 2026, 11 a.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

6.5

CVSS3.1

CVE-2026-34887 - WordPress Kubio AI Page Builder plugin <= 2.7.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: from n/a through 2.7.0.

πŸ“… Published: March 31, 2026, 10:19 a.m. πŸ”„ Last Modified: April 24, 2026, 6:08 p.m.

7

CVSS4.0

CVE-2026-4400 - Multiple vulnerabilities in 1millionbot Millie chatbot

Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by simply changing the conversation ID. The vulnerability is present in the endpoint 'api.1millionbot.com/api/public/conversations/' and, if exploited, coul…

πŸ“… Published: March 31, 2026, 10:12 a.m. πŸ”„ Last Modified: April 14, 2026, 9:31 p.m.

8.7

CVSS4.0

CVE-2026-4399 - Multiple vulnerabilities in 1millionbot Millie chatbot

Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a way that, upon receiving an affirmative response ('true'), the model executes the injected instruction)…

πŸ“… Published: March 31, 2026, 10:10 a.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.

9.1

CVSS3.1

CVE-2025-15618 - Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret k…

Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use. This key is inten…

πŸ“… Published: March 31, 2026, 10:04 a.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.

5.3

CVSS4.0

CVE-2026-5197 - code-projects Student Membership System delete_user.php sql injection

A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

πŸ“… Published: March 31, 2026, 10 a.m. πŸ”„ Last Modified: April 24, 2026, 6:11 p.m.

9.3

CVSS4.0

CVE-2026-4317 - SQL inyection in Umami Software application

SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to execute arbitrary SQL commands in the database.Specifically, they could manipulate the value of the 'timezone' request parameter by includin…

πŸ“… Published: March 31, 2026, 9:53 a.m. πŸ”„ Last Modified: April 1, 2026, 2:24 p.m.

5.3

CVSS4.0

CVE-2026-5196 - code-projects Student Membership System delete_member.php sql injection

A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be us…

πŸ“… Published: March 31, 2026, 9 a.m. πŸ”„ Last Modified: April 24, 2026, 6:11 p.m.

9.3

CVSS4.0

CVE-2026-3107 - Multiple vulnerabilities in Teampass

Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import process, allowing malicio…

πŸ“… Published: March 31, 2026, 8:58 a.m. πŸ”„ Last Modified: April 7, 2026, 3:36 p.m.

5.1

CVSS4.0

CVE-2025-41357 - Reflected Cross-Site Scripting on Anon Proxy Server

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or …

πŸ“… Published: March 31, 2026, 8:58 a.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.
Total resulsts: 349182
Page 784 of 34,919
Β« previous page Β» next page
Filters