9.1

CVSS3.1

CVE-2025-40538 - SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On W…

πŸ“… Published: Feb. 24, 2026, 7:40 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

8.8

CVSS3.1

CVE-2025-15386 - Responsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

πŸ“… Published: Feb. 24, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-15589 - MuYuCMS Template Management Template.php delete_dir_file path traversal

A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulation of the argument temn/tp causes path traversal. It is possible to initiate the attack remotely. T…

πŸ“… Published: Feb. 24, 2026, 5:52 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:25 p.m.

4.3

CVSS3.1

CVE-2026-24314 - Information Disclosure vulnerability in S/4HANA (Manage Payment Media)

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.

πŸ“… Published: Feb. 24, 2026, 5:23 a.m. πŸ”„ Last Modified: April 17, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-3070 - SourceCodester Modern Image Gallery App upload.php cross site scripting

A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filename results in cross site scripting. The attack may be launched remotely. The exploit is now public a…

πŸ“… Published: Feb. 24, 2026, 4:32 a.m. πŸ”„ Last Modified: April 17, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2026-3069 - itsourcecode Document Management System edtlbls.php sql injection

A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may …

πŸ“… Published: Feb. 24, 2026, 4:02 a.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

6.9

CVSS4.0

CVE-2026-3068 - itsourcecode Document Management System deluser.php sql injection

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the publ…

πŸ“… Published: Feb. 24, 2026, 3:32 a.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

5.3

CVSS4.0

CVE-2026-3067 - HummerRisk Archive Extraction CommandUtils.java extractZip path traversal

A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/CommandUtils.java of the component Archive Extraction. The manipulation leads to path traversal. …

πŸ“… Published: Feb. 24, 2026, 3:32 a.m. πŸ”„ Last Modified: April 17, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-3066 - HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection

A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformUtils.java of the component Cloud Compliance Scanning. Executing a manipulation can lead to command i…

πŸ“… Published: Feb. 24, 2026, 3:02 a.m. πŸ”„ Last Modified: April 17, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2026-27461 - Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE clause

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded and the value field is concatenated directly into RLIKE clauses without sanitization or parameterized…

πŸ“… Published: Feb. 24, 2026, 2:50 a.m. πŸ”„ Last Modified: April 17, 2026, 4 p.m.
Total resulsts: 347728
Page 1325 of 34,773
Β« previous page Β» next page
Filters