7.5

CVSS3.1

CVE-2026-30077 -

OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example input in hex stream is 80 00 00 0E 00 00 01 00 0F 80 02 02 40 00 58 00 01 88.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

5.3

CVSS3.1

CVE-2026-29909 -

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:38 a.m.

9.8

CVSS3.1

CVE-2026-30305 -

Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fai…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 8 p.m.

7.7

CVSS3.1

CVE-2026-29925 -

Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:38 a.m.

6.1

CVSS3.1

CVE-2026-30556 - Reflected XSS via msg Parameter in SourceCodester Sales and Inventory System 1.0

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the index.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 7:54 a.m.

7.1

CVSS3.1

CVE-2026-34472 -

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including the default administrator password, WLAN PSK,…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 8 p.m.

7.4

CVSS3.1

CVE-2026-33643 -

SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file plugins/mysql/lib/column.go.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:38 a.m.

6.1

CVSS3.1

CVE-2026-30566 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script …

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 7:54 a.m.

6.1

CVSS3.1

CVE-2026-30563 -

A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update_details.php file. The application fails to sanitize the "website" parameter provided in a POST request. This allows authenticated attackers to inject…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:11 a.m.

9.8

CVSS3.1

CVE-2026-30306 - Prompt Injection Causing Arbitrary Command Execution in SakaDev Visual Studio Code Extension

In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be pote…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 8 p.m.
Total resulsts: 349182
Page 806 of 34,919
Β« previous page Β» next page
Filters