6.9

CVSS4.0

CVE-2026-6568 - kodcloud KodExplorer Public Share share.class.php initShareOld path traversal

A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack can be initiated rem…

πŸ“… Published: April 19, 2026, 9:45 a.m. πŸ”„ Last Modified: April 19, 2026, 9:45 a.m.

5.3

CVSS4.0

CVE-2026-6564 - EMQ EMQX Enterprise Session Handling improper authorization

A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vend…

πŸ“… Published: April 19, 2026, 9:30 a.m. πŸ”„ Last Modified: April 19, 2026, 9:30 a.m.

8.7

CVSS4.0

CVE-2026-6563 - H3C Magic B1 aspForm SetAPWifiorLedInfoById buffer overflow

A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to t…

πŸ“… Published: April 19, 2026, 8:30 a.m. πŸ”„ Last Modified: April 19, 2026, 8:30 a.m.

6.9

CVSS4.0

CVE-2026-6562 - dameng100 muucmf index.html getListByPage sql injection

A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a manipulation of the argument keyword can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.…

πŸ“… Published: April 19, 2026, 8:15 a.m. πŸ”„ Last Modified: April 19, 2026, 8:15 a.m.

5.1

CVSS4.0

CVE-2026-6561 - EyouCMS Index.php edit_adminlogo unrestricted upload

A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is possible to be carried out remotely. The exploit i…

πŸ“… Published: April 19, 2026, 7:15 a.m. πŸ”„ Last Modified: April 20, 2026, 2:55 p.m.

8.7

CVSS4.0

CVE-2026-6560 - H3C Magic B0 aspForm Edit_BasicSSID buffer overflow

A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_BasicSSID of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicl…

πŸ“… Published: April 19, 2026, 6:45 a.m. πŸ”„ Last Modified: April 19, 2026, 6:45 a.m.

5.3

CVSS4.0

CVE-2026-6559 - Wavlink WL-WN579A3 login.cgi sub_401F80 cross site scripting

A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. T…

πŸ“… Published: April 19, 2026, 5:15 a.m. πŸ”„ Last Modified: April 19, 2026, 5:15 a.m.

6.4

CVSS3.1

CVE-2026-0868 - EMC Scheduling Manager <= 4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via calend…

The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly shortcode in all versions up to, and including, 4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p…

πŸ“… Published: April 19, 2026, 3:26 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

6.1

CVSS3.1

CVE-2026-6861 - Emacs: emacs: memory corruption vulnerability when processing svg css

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a deni…

πŸ“… Published: April 19, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

9.4

CVSS4.0

CVE-2026-41242 - protobufjs has an arbitrary code execution issue

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the i…

πŸ“… Published: April 18, 2026, 4:18 p.m. πŸ”„ Last Modified: April 18, 2026, 4:18 p.m.
Total resulsts: 346094
Page 93 of 34,610
Β« previous page Β» next page
Filters