5.3

CVSS4.0

CVE-2026-4485 - itsourcecode College Management System search_student.php sql injection

A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/search_student.php. The manipulation of the argument Search leads to sql injection. The attack is possible to be carried out remotely. The exploit has been di…

πŸ“… Published: March 20, 2026, 1:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

6.1

CVSS3.1

CVE-2026-31382 - Gainsight Assist reflected XSS/HTML injection

The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.

πŸ“… Published: March 20, 2026, 1:04 p.m. πŸ”„ Last Modified: April 16, 2026, 3:02 p.m.

5.3

CVSS3.1

CVE-2026-31381 - Gainsight Assist plugin information disclosure

An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.

πŸ“… Published: March 20, 2026, 1:02 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 a.m.

8.1

CVSS3.1

CVE-2026-4434 -

Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

πŸ“… Published: March 20, 2026, 12:52 p.m. πŸ”„ Last Modified: March 30, 2026, 8:58 p.m.

9.3

CVSS3.1

CVE-2026-33136 - WeGIA has Reflected Cross-Site Scripting (XSS) in `listar_memorandos_ativos.php` via `sccd` paramet…

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inject arbitrary JavaScript or HTML tags into the sccd GET parameter, which is then directly echoed in…

πŸ“… Published: March 20, 2026, 10:41 a.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.

9.3

CVSS3.1

CVE-2026-33135 - WeGIA has Reflected Cross-Site Scripting (XSS) in `novo_memorandoo.php` via `sccs` parameter

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into the sccs GET parameter, which is directly echoed into the HTML response withou…

πŸ“… Published: March 20, 2026, 10:38 a.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.

9.3

CVSS3.1

CVE-2026-33134 - WeGIA has Authenticated Time-Based Blind SQL Injection in `restaurar_produto.php` via `id_produto` …

WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability allows an authenticated attacker to inject arbitrary SQL commands via the id_produto GET parameter, …

πŸ“… Published: March 20, 2026, 10:35 a.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.

8.6

CVSS4.0

CVE-2026-33133 - WeGIA has an arbitrary SQL execution vulnerability via crafted backup archive

WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary SQL statements that create rogue administrator acc…

πŸ“… Published: March 20, 2026, 10:31 a.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.

5.3

CVSS3.1

CVE-2026-33132 - ZITADEL is missing enforcement of organization scopes

ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users to bypass organization enforcement during authentication. Zitadel allows applications to enforce an organzation context during authentication using scopes (urn:zitadel:iam:org:id:{…

πŸ“… Published: March 20, 2026, 10:21 a.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.

7.4

CVSS3.1

CVE-2026-33131 - h3 has a middleware bypass with one gadget

H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middleware bypass. When event.url, event.url.hostname, or event.url._url is accessed, such as in a logging middleware, the _…

πŸ“… Published: March 20, 2026, 10:16 a.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.
Total resulsts: 349182
Page 1017 of 34,919
Β« previous page Β» next page
Filters