5.1

CVSS4.0

CVE-2025-41356 - Reflected Cross-Site Scripting in Anon Proxy Server

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or …

πŸ“… Published: March 31, 2026, 8:53 a.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

9.3

CVSS4.0

CVE-2026-3106 - Multiple vulnerabilities in Teampass

Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseΓ±a' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information en…

πŸ“… Published: March 31, 2026, 8:51 a.m. πŸ”„ Last Modified: April 7, 2026, 3:36 p.m.

5.1

CVSS4.0

CVE-2025-41355 - Reflected Cross-Site Scripting on Anon Proxy Server

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies,…

πŸ“… Published: March 31, 2026, 8:48 a.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

7.1

CVSS3.1

CVE-2025-10559 - Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag…

A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to read or write files in specific directories on the server.

πŸ“… Published: March 31, 2026, 8:41 a.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

8.7

CVSS3.1

CVE-2025-10553 - Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Fac…

A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

πŸ“… Published: March 31, 2026, 8:41 a.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

8.7

CVSS3.1

CVE-2025-10551 - Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborati…

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

πŸ“… Published: March 31, 2026, 8:38 a.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.

6.9

CVSS4.0

CVE-2026-5195 - code-projects Student Membership System User Registration sql injection

A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the component User Registration Handler. Executing a manipulation can lead to sql injection. The attack can be launched remotely.

πŸ“… Published: March 31, 2026, 8:15 a.m. πŸ”„ Last Modified: April 24, 2026, 6:11 p.m.

4.8

CVSS4.0

CVE-2026-5186 - Nothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double free

A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler. This manipulation causes double free. The attack requires local access. The exploit has been made available to the public a…

πŸ“… Published: March 31, 2026, 7:30 a.m. πŸ”„ Last Modified: April 24, 2026, 6:11 p.m.

4.8

CVSS4.0

CVE-2026-5185 - Nothings stb_image Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflow

A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handler. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has be…

πŸ“… Published: March 31, 2026, 6:45 a.m. πŸ”„ Last Modified: April 24, 2026, 6:11 p.m.

5.3

CVSS4.0

CVE-2026-5184 - TRENDnet TEW-713RE setSysAdm command injection

A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file /goform/setSysAdm. The manipulation of the argument admuser leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.…

πŸ“… Published: March 31, 2026, 6:45 a.m. πŸ”„ Last Modified: April 1, 2026, 2:24 p.m.
Total resulsts: 349182
Page 785 of 34,919
Β« previous page Β» next page
Filters