5.3

CVSS4.0

CVE-2026-4234 - SSCMS DDL SitesAddController.Submit.cs sql injection

A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddController.Submit.cs of the component DDL Handler. The manipulation of the argument tableHandWrite results in sql injection. The attack can be executed remotely. The exploit has been rele…

πŸ“… Published: March 16, 2026, 10:32 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

4.8

CVSS4.0

CVE-2026-3024 - Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma application web

Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/configuracion/agenda/modelo-formulario-evento'. A user with permission to create personalized accounts could exploit this vulnerability simply by creating a malicious survey …

πŸ“… Published: March 16, 2026, 10:13 a.m. πŸ”„ Last Modified: March 30, 2026, 8 a.m.

5.3

CVSS4.0

CVE-2026-3023 - Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/pets/print-tags'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose of injecting NoSQL commands, allow…

πŸ“… Published: March 16, 2026, 10:12 a.m. πŸ”„ Last Modified: March 30, 2026, 8 a.m.

7.1

CVSS4.0

CVE-2026-3022 - Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/generate-hospitalization-summary'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose o…

πŸ“… Published: March 16, 2026, 10:11 a.m. πŸ”„ Last Modified: March 30, 2026, 8 a.m.

7.1

CVSS4.0

CVE-2026-3021 - Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/centro/equipo/empleado'. This vulnerability could allow an authenticated user to alter a GET request to the affected endpoint for the purpose of injecting special NoSQL c…

πŸ“… Published: March 16, 2026, 10:11 a.m. πŸ”„ Last Modified: March 30, 2026, 8 a.m.

8.6

CVSS4.0

CVE-2026-3020 - Identity based authorization bypass vulnerability (IDOR) in the Wakyma application web

Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing the victim's email address, validating the new email address, and requesting a new password. This could allow them to take complete control of other use…

πŸ“… Published: March 16, 2026, 10:09 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

5.3

CVSS4.0

CVE-2026-4233 - ThingsGateway download path traversal

A vulnerability was identified in ThingsGateway 12. This affects an unknown part of the file /api/file/download. The manipulation of the argument fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was cont…

πŸ“… Published: March 16, 2026, 10:02 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

6.9

CVSS4.0

CVE-2026-3111 - Multiple vulnerabilities on the Educativa Campus

Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuarios/[ID]/[username]/thumb_AAxAA.jpg' (translated as 80x90 and 40x45). Successful exploitation of this vulnerability could allow an unauthenticated attacker to access the profile ph…

πŸ“… Published: March 16, 2026, 9:37 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

8.7

CVSS4.0

CVE-2026-3110 - Multiple vulnerabilities on the Educativa Campus

Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/admin_usuarios.cgi?filtro_estado=T&wAccion=listado_xlsx&wBuscar=&wFiltrar=&wOrden=alta_usuario&wid_cursoActual=[ID]' where the data of users enrolled in the course is exported. Su…

πŸ“… Published: March 16, 2026, 9:36 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

6.9

CVSS4.0

CVE-2026-4232 - Tiandy Integrated Management Platform getAuthorityByUserId sql injection

A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /rest/user/getAuthorityByUserId. Executing a manipulation of the argument userId can lead to sql injection. The attack may be launched remotely. The explo…

πŸ“… Published: March 16, 2026, 9:32 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.
Total resulsts: 349182
Page 1100 of 34,919
Β« previous page Β» next page
Filters