7.6

CVSS3.1

CVE-2026-29924 -

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

6.5

CVSS3.1

CVE-2026-29597 -

DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive configuration files by force browsing the β€œ/Admin/file_manager/file_details.asp” endpoint and manipulating the β€œfile” parameter. By referencing specific fi…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

7.4

CVSS3.1

CVE-2026-29953 -

SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins/postgres/lib/column.go.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:38 a.m.

6.1

CVSS3.1

CVE-2026-30082 - Stored Cross‑Site Scripting in IngEstate Server Software Package List Edit Feature

Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters.

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:11 a.m.

8.8

CVSS3.1

CVE-2026-33373 -

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state transitions. Specifically, tokens generated after oper…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 8 p.m.

6.1

CVSS3.1

CVE-2026-30565 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script o…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 7:54 a.m.

6.1

CVSS3.1

CVE-2026-30564 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script o…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:11 a.m.

9.3

CVSS3.1

CVE-2026-30562 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 7:55 a.m.

6.1

CVSS3.1

CVE-2026-30559 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_sales.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

6.1

CVSS3.1

CVE-2026-30558 - Reflected Cross‑Site Scripting in SourceCodester Sales and Inventory System 1.0 via msg Parameter

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_customer.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or H…

πŸ“… Published: March 30, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.
Total resulsts: 349182
Page 807 of 34,919
Β« previous page Β» next page
Filters