8.1

CVSS3.1

CVE-2026-40960 - Crafted Module Enables Unauthorized Access to Insecure Environment in Luanti

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.

πŸ“… Published: April 16, 2026, 12:54 a.m. πŸ”„ Last Modified: April 17, 2026, 5 a.m.

9.3

CVSS3.1

CVE-2026-40959 - Lua sandbox escape via crafted module in Luanti using LuaJIT

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

πŸ“… Published: April 16, 2026, 12:51 a.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.7

CVSS4.0

CVE-2026-40502 - OpenHarness Remote Administrative Command Injection via Gateway Handler

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execu…

πŸ“… Published: April 16, 2026, 12:08 a.m. πŸ”„ Last Modified: April 17, 2026, 6:30 a.m.

7.1

CVSS4.0

CVE-2026-40503 - OpenHarness Path Traversal Information Disclosure via /memory show

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memo…

πŸ“… Published: April 16, 2026, 12:08 a.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

6.5

CVSS3.1

CVE-2026-37100 - Unauthenticated BLE Control Access on Yamaha SR-B30A Sound Bar

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio range to connect without authentication via the Sound Bar Remote protocol

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:26 a.m.

9.8

CVSS3.1

CVE-2026-37345 - SQL Injection in Vehicle Parking Area Management System v1.0

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 6:30 a.m.

0.0

CVE-2026-37342 - SQL Injection in SourceCodester Vehicle Parking Area Management System

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:18 a.m.

4.7

CVSS3.1

CVE-2026-37346 - SQL Injection in /payroll/view_account.php of SourceCodester Payroll Management System v1.0

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 5 a.m.

7.3

CVSS3.1

CVE-2026-37336 - SQL Injection in /music/view_music.php of Simple Music Cloud Community System

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 6 a.m.

0.0

CVE-2026-37340 - Simple Music Cloud Community System v1.0 – SQL Injection in /music/edit_music.php

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:14 a.m.
Total resulsts: 345788
Page 97 of 34,579
Β« previous page Β» next page
Filters