5.3

CVSS3.1

CVE-2026-4911 - Booking Package <= 1.7.06 - Unauthenticated Price Manipulation via 'amount' Parameter

The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the commitStripe() function i…

πŸ“… Published: April 28, 2026, 6:45 a.m. πŸ”„ Last Modified: April 28, 2026, 6:45 a.m.

6.9

CVSS4.0

CVE-2026-7237 - AgiFlow scaffold-mcp write-to-file Tool index.ts path traversal

A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold-mcp/src/server/index.ts of the component write-to-file Tool. The manipulation of the argument file_path results in path traversal. The attack may be …

πŸ“… Published: April 28, 2026, 6:45 a.m. πŸ”„ Last Modified: April 28, 2026, 6:45 a.m.

5.9

CVSS3.1

CVE-2026-40966 - VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as …

πŸ“… Published: April 28, 2026, 6:42 a.m. πŸ”„ Last Modified: April 28, 2026, 6:49 a.m.

6.9

CVSS4.0

CVE-2026-7235 - ErlichLiu claude-agent-sdk-master route.ts path traversal

A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca1747bf. Affected by this vulnerability is an unknown functionality of the file app/api/agent-output/route.ts. The manipulation of the argument outputFile leads to path traversal. …

πŸ“… Published: April 28, 2026, 6:30 a.m. πŸ”„ Last Modified: April 28, 2026, 6:30 a.m.

6.9

CVSS4.0

CVE-2026-7234 - BrowserOperator browser-operator-core server.js startsWith path traversal

A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit …

πŸ“… Published: April 28, 2026, 6:15 a.m. πŸ”„ Last Modified: April 28, 2026, 6:15 a.m.

8.2

CVSS3.1

CVE-2026-40967 -

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query. Affected versions: Spring AI: 1.0.0 …

πŸ“… Published: April 28, 2026, 6:03 a.m. πŸ”„ Last Modified: April 28, 2026, 6:03 a.m.

4.8

CVSS4.0

CVE-2026-7233 - Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly …

πŸ“… Published: April 28, 2026, 6 a.m. πŸ”„ Last Modified: April 28, 2026, 6 a.m.

0.0

CVE-2026-5306 - Check & Log Email < 2.0.13 - Unauthenticated Stored XSS

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled

πŸ“… Published: April 28, 2026, 6 a.m. πŸ”„ Last Modified: April 28, 2026, 6 a.m.

5.3

CVSS4.0

CVE-2026-7230 - SourceCodester Safety Anger Pad cross site scripting

A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manipulation of the argument angerDisplay results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.

πŸ“… Published: April 28, 2026, 5:45 a.m. πŸ”„ Last Modified: April 28, 2026, 5:45 a.m.

5.3

CVSS4.0

CVE-2026-7229 - code-projects Coaching Management System POST reply.php sql injection

A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manipulation of the argument complaintreply results in sql injection. It is possible to initiate the atta…

πŸ“… Published: April 28, 2026, 5:30 a.m. πŸ”„ Last Modified: April 28, 2026, 5:30 a.m.
Total resulsts: 347738
Page 85 of 34,774
Β« previous page Β» next page
Filters