6.9

CVSS4.0

CVE-2026-22888 - Improper Input Verification Enabling Unauthorized Portal Settings Modification

Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.

πŸ“… Published: Feb. 2, 2026, 6:37 a.m. πŸ”„ Last Modified: April 18, 2026, 12:45 a.m.

6.8

CVSS4.0

CVE-2026-22881 - XSS in Cybozu Garoon Allows Password Reset

Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.

πŸ“… Published: Feb. 2, 2026, 6:37 a.m. πŸ”„ Last Modified: April 18, 2026, 12:45 a.m.

6.9

CVSS4.0

CVE-2026-20711 - Cross‑Site Scripting in Garoon Email Enables Password Reset for Any User

Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.

πŸ“… Published: Feb. 2, 2026, 6:37 a.m. πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

4.3

CVSS3.1

CVE-2026-0658 - Five Star Restaurant Reservations < 2.7.9 - Arbitrary Bookings Deletion via CSRF

The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks.

πŸ“… Published: Feb. 2, 2026, 6 a.m. πŸ”„ Last Modified: April 18, 2026, 12:45 a.m.

7.1

CVSS3.1

CVE-2025-15396 - Library Viewer < 3.2.0 - Reflected Cross-Site Scripting

The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Feb. 2, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-15030 - User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

πŸ“… Published: Feb. 2, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2026-1746 - JeecgBoot Online Report API loadDictItemByKeyword sql injection

A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the component Online Report API. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit is p…

πŸ“… Published: Feb. 2, 2026, 5:32 a.m. πŸ”„ Last Modified: April 18, 2026, 12:45 a.m.

5.3

CVSS4.0

CVE-2026-1745 - SourceCodester Medical Certificate Generator App cross-site request forgery

A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

πŸ“… Published: Feb. 2, 2026, 5:02 a.m. πŸ”„ Last Modified: April 18, 2026, 12:45 a.m.

9.8

CVSS3.1

CVE-2026-25202 - Hardcoded Database Credentials in MagicINFO 9 Server Allow Remote Administrative Access

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.

πŸ“… Published: Feb. 2, 2026, 4:49 a.m. πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

8.8

CVSS3.1

CVE-2026-25201 -

An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.

πŸ“… Published: Feb. 2, 2026, 4:49 a.m. πŸ”„ Last Modified: April 18, 2026, 1 a.m.
Total resulsts: 349182
Page 1865 of 34,919
Β« previous page Β» next page
Filters