8.7

CVSS4.0

CVE-2026-35185 - HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client Iโ€ฆ

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows โ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.

8.7

CVSS4.0

CVE-2026-35184 - EcclesiaCRM has a Critical SQL Injection

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.

๐Ÿ“… Published: April 6, 2026, 7:21 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.

5.3

CVSS4.0

CVE-2026-5681 - itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection

A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument emp_id causes sql injection. The attack is possible to be carried out remotely. The exploiโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:15 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:54 a.m.

7.1

CVSS3.1

CVE-2026-35183 - Brave CMS has an Insecure Direct Object Reference in Article Image Deletion

Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located in app/Http/Controllers/Dashboard/ArticleController.php within the deleteImage method. The endpoint accepts a filename from the URL bโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:11 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.

8.8

CVSS3.1

CVE-2026-35182 - Missing Authorization Privilege Escalation

Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to chโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:10 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.

4.3

CVSS3.1

CVE-2026-35181 - WWBN AVideo Affected by CSRF on Player Skin Configuration via admin/playerUpdate.json.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based security check via ignoreTableSecurityCheck(), removingโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:09 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.

7.5

CVSS3.1

CVE-2026-35172 - Distribution has stale blob access resurrection via repo-scoped redis descriptor cache invalidation

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digestโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:08 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.

4.3

CVSS3.1

CVE-2026-35180 - WWBN AVideo affected by CSRF on Site Customization Endpoint Enables Logo Overwrite via Base64 File โ€ฆ

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token validation and writes uploaded logo files to disk before the ORM's domain-based security check executes. Combined with SameSitโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:06 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.

5.3

CVSS3.1

CVE-2026-35179 - WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts user-controlled parameters including an access tokenโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:05 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.

9.3

CVSS4.0

CVE-2026-35178 - Workbench Affected by Remote Code Execution (RCE) via Malicious Cookie in Timezone Conversion

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerability in the timezone conversion flow, which processes attacker-controlled cookie values in an unsaโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:01 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 8:16 p.m.
Total resulsts: 342654
Page 9 of 34,266
ยซ previous page ยป next page
Filters