6.9

CVSS4.0

CVE-2026-6582 - TransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details…

A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/controllers/vector_dbs.py of the component Vector Database Management Endpoint. Executing a manipulation can lead to missing authentication. The attac…

πŸ“… Published: April 19, 2026, 10:45 p.m. πŸ”„ Last Modified: April 19, 2026, 10:45 p.m.

8.7

CVSS4.0

CVE-2026-6581 - H3C Magic B1 aspForm SetMobileAPInfoById buffer overflow

A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now p…

πŸ“… Published: April 19, 2026, 10:30 p.m. πŸ”„ Last Modified: April 19, 2026, 10:30 p.m.

6.9

CVSS4.0

CVE-2026-6580 - liangliangyy DjangoBlog Amap API Call views.py hard-coded key

A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler. Such manipulation of the argument key leads to use of hard-coded cryptographic key . The attack may be launche…

πŸ“… Published: April 19, 2026, 10:15 p.m. πŸ”„ Last Modified: April 19, 2026, 10:15 p.m.

6.9

CVSS4.0

CVE-2026-6579 - liangliangyy DjangoBlog Clean Endpoint views.py missing authentication

A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the publ…

πŸ“… Published: April 19, 2026, 10 p.m. πŸ”„ Last Modified: April 19, 2026, 10 p.m.

6.3

CVSS4.0

CVE-2026-6578 - liangliangyy DjangoBlog Setting settings.py hard-coded credentials

A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of the argument SECRET_KEY results in hard-coded credentials. The attack can be launched remotely. The…

πŸ“… Published: April 19, 2026, 9:15 p.m. πŸ”„ Last Modified: April 19, 2026, 9:15 p.m.

6.9

CVSS4.0

CVE-2026-6577 - liangliangyy DjangoBlog logtracks Endpoint views.py missing authentication

A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly av…

πŸ“… Published: April 19, 2026, 7:30 p.m. πŸ”„ Last Modified: April 19, 2026, 7:30 p.m.

5.3

CVSS4.0

CVE-2026-6576 - liangliangyy DjangoBlog WeChat Bot commonapi.py CommandHandler command injection

A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat Bot Interface. Executing a manipulation of the argument Source can lead to command injection. It is possibl…

πŸ“… Published: April 19, 2026, 7 p.m. πŸ”„ Last Modified: April 19, 2026, 7 p.m.

6.9

CVSS4.0

CVE-2026-6574 - osuuu LightPicture API Upload Endpoint lp.sql hard-coded credentials

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The e…

πŸ“… Published: April 19, 2026, 1:30 p.m. πŸ”„ Last Modified: April 19, 2026, 1:30 p.m.

5.3

CVSS4.0

CVE-2026-6573 - PHPEMS Instant Exam Creation exams.master.php temppage server-side request forgery

A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attack can be executed remotely. …

πŸ“… Published: April 19, 2026, 12:45 p.m. πŸ”„ Last Modified: April 20, 2026, 3:19 p.m.

6.3

CVSS4.0

CVE-2026-6572 - Collabora KodExplorer fileUpload Endpoint share.class.php improper authorization

A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app/controller/share.class.php of the component fileUpload Endpoint. The manipulation of the argument fileUpload leads to improper authorization. Remote …

πŸ“… Published: April 19, 2026, 12:15 p.m. πŸ”„ Last Modified: April 19, 2026, 12:15 p.m.
Total resulsts: 346087
Page 91 of 34,609
Β« previous page Β» next page
Filters