5.4

CVSS3.1

CVE-2026-32118 - OpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation text

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map ("clickmap") form allows any authenticated clinician to inject arbitrary JavaScript that executes in the browser of …

📅 Published: March 11, 2026, 8:46 p.m. 🔄 Last Modified: March 20, 2026, 3:37 p.m.

6.8

CVSS3.1

CVE-2026-32112 - ha-mcp has XSS via Unescaped HTML in OAuth Consent Form

ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth endpoint and convince the server operator to follow a crafted authorization URL could execute JavaS…

📅 Published: March 11, 2026, 8:42 p.m. 🔄 Last Modified: March 20, 2026, 3:37 p.m.

5.3

CVSS3.1

CVE-2026-32111 - ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle

ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/api/config with no URL validation. An unauthenticated attacker can submit arbitrary URLs to perform internal network re…

📅 Published: March 11, 2026, 8:41 p.m. 🔄 Last Modified: March 20, 2026, 3:37 p.m.

8.3

CVSS3.1

CVE-2026-32110 - SiYuan has a Full-Read SSRF via /api/network/forwardProxy

SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenticated users to make arbitrary HTTP requests from the server. The endpoint accepts a user-controlled URL and makes HTTP requests to it, returning the full response body and headers…

📅 Published: March 11, 2026, 8:38 p.m. 🔄 Last Modified: March 20, 2026, 3:37 p.m.

5.1

CVSS4.0

CVE-2026-3956 - xierongwkhd weimai-wetapp Admin_AdminUserController.java getAdmins sql injection

A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This affects the function getAdmins of the file source-code/src/main/java/com/moke/wp/wx_weimai/controller/admin/Admin_AdminUserController.java. Performing a manipulation of the argument keywor…

📅 Published: March 11, 2026, 8:32 p.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

5.3

CVSS4.0

CVE-2026-3955 - elecV2P jsfile Endpoint wbjs.js runJSFile code injection

A security vulnerability has been detected in elecV2P up to 3.8.3. Affected by this issue is the function runJSFile of the file source-code/elecV2P-master/webser/wbjs.js of the component jsfile Endpoint. Such manipulation leads to code injection. The attack may be launched remotely. The exploit has…

📅 Published: March 11, 2026, 8:32 p.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

6.8

CVSS4.0

CVE-2026-2640 - Local Privilege Escalation: Termination of Privileged Processes in Lenovo PC Manager

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

📅 Published: March 11, 2026, 8:23 p.m. 🔄 Last Modified: March 20, 2026, 3:37 p.m.

6.8

CVSS4.0

CVE-2026-1717 - Local Authenticated Process Termination via Input Validation in LenovoProductivitySystemAddin

An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.

📅 Published: March 11, 2026, 8:22 p.m. 🔄 Last Modified: March 25, 2026, 6:22 p.m.

6.9

CVSS4.0

CVE-2026-1716 - Local Privilege Escalation via Input Validation in Lenovo Vantage & Baiying DeviceSettingsSystemAdd…

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.

📅 Published: March 11, 2026, 8:22 p.m. 🔄 Last Modified: March 25, 2026, 6:23 p.m.

6.9

CVSS4.0

CVE-2026-1715 - Input Validation Vulnerability Allowing Local Privilege Escalation in Lenovo DeviceSettingsSystemAd…

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.

📅 Published: March 11, 2026, 8:22 p.m. 🔄 Last Modified: March 25, 2026, 6:23 p.m.
Total resulsts: 349182
Page 1168 of 34,919
« previous page » next page
Filters