4.3

CVSS3.1

CVE-2026-40968 - Spring gRPC SecurityContext leaks across requests on authorization failure

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Sโ€ฆ

๐Ÿ“… Published: April 28, 2026, 1:42 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:42 p.m.

5.1

CVSS4.0

CVE-2026-7282 - SourceCodester Pharmacy Sales and Inventory System ajax.php delete_expired sql injection

A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is โ€ฆ

๐Ÿ“… Published: April 28, 2026, 1:30 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-7281 - SourceCodester Pharmacy Sales and Inventory System index.php supplier cross site scripting

A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier. Executing a manipulation of the argument Name can lead to cross site scripting. The attack may be performed from remote. The โ€ฆ

๐Ÿ“… Published: April 28, 2026, 1:15 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:15 p.m.

4.7

CVSS4.0

CVE-2026-40552 - Remote Code Execution in mpGabinet

mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifying its storage path in the database to reference an attacker-controlled remote โ€ฆ

๐Ÿ“… Published: April 28, 2026, 1:13 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:13 p.m.

8.4

CVSS4.0

CVE-2026-40551 - Use of Client-Side Authentication in mpGabinet

mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19โ€ฆ

๐Ÿ“… Published: April 28, 2026, 1:13 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:13 p.m.

6.9

CVSS4.0

CVE-2026-40550 - Privilege Escalation in mpGabinet

mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running application instance connected to the backend server can extract database credentials from the applicationโ€™s memory by inspectingโ€ฆ

๐Ÿ“… Published: April 28, 2026, 1:12 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:12 p.m.

0.0

CVE-2026-6706 -

Improper access control in the vault documentation feature in Devolutions Server 2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.

๐Ÿ“… Published: April 28, 2026, 1:11 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:11 p.m.

6.7

CVSS4.0

CVE-2026-5944 - Cisco Intersight Device Connector for Nutanix Prism Central Unauthenticated API Access

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticateโ€ฆ

๐Ÿ“… Published: April 28, 2026, 1:06 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:06 p.m.

6.9

CVSS4.0

CVE-2026-7272 - WilliamCloudQi matlab-mcp-server MCP index.ts execute_matlab_code path traversal

A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can leโ€ฆ

๐Ÿ“… Published: April 28, 2026, 1 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1 p.m.

4.3

CVSS3.1

CVE-2026-7309 - Openshift-controller-manager: openshift container platform: information disclosure via environment โ€ฆ

A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantiate` API. This incomplete fix for a previous vulneโ€ฆ

๐Ÿ“… Published: April 28, 2026, 12:33 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 12:33 p.m.
Total resulsts: 347806
Page 87 of 34,781
ยซ previous page ยป next page
Filters