9.3

CVSS4.0

CVE-2020-36875 - AccessAlly < 3.3.2 Unauthenticated Arbitrary PHP Code Execution

AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and execute arbitrary PHP in the context of the WordPress web ser…

📅 Published: Jan. 9, 2026, 4:41 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-15494 - RainyGao DocSys UserMapper.xml sql injection

A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSystem/mapping/UserMapper.xml. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public an…

📅 Published: Jan. 9, 2026, 4:32 p.m. 🔄 Last Modified: Feb. 23, 2026, 8:26 a.m.

5.3

CVSS4.0

CVE-2025-15493 - RainyGao DocSys ReposAuthMapper.xml sql injection

A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMapper.xml. Executing a manipulation of the argument searchWord can lead to sql injection. It is possible to launch the attack remotely. The exploit has…

📅 Published: Jan. 9, 2026, 4:32 p.m. 🔄 Last Modified: Feb. 23, 2026, 8:25 a.m.

7.7

CVSS4.0

CVE-2026-22196 - GestSup < 3.2.60 SQL Injection in Ticket Creation

GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Succe…

📅 Published: Jan. 9, 2026, 4:23 p.m. 🔄 Last Modified: April 16, 2026, 6:30 p.m.

5.1

CVSS4.0

CVE-2026-22198 - GestSup < 3.2.60 Stored XSS in API Error Logs

GestSup versions prior to 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API error logging functionality. By sending an API request with a crafted X-API-KEY header value (for example, to /api/v1/ticket.php), an unauthenticated attacker can cause attacker-…

📅 Published: Jan. 9, 2026, 4:19 p.m. 🔄 Last Modified: April 16, 2026, 6:30 p.m.

7.5

CVSS4.0

CVE-2026-22197 - GestSup < 3.2.60 Multiple SQL Injections in Asset List

GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets are incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate d…

📅 Published: Jan. 9, 2026, 4:18 p.m. 🔄 Last Modified: April 16, 2026, 6:30 p.m.

7.7

CVSS4.0

CVE-2026-22195 - GestSup < 3.2.60 SQL Injection in Search Bar

GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can res…

📅 Published: Jan. 9, 2026, 4:18 p.m. 🔄 Last Modified: April 16, 2026, 6:30 p.m.

8.9

CVSS4.0

CVE-2026-22194 - GestSup <= 3.2.56 CSRF Allows Privileged Actions

GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This…

📅 Published: Jan. 9, 2026, 4:17 p.m. 🔄 Last Modified: April 18, 2026, 4:45 p.m.

10

CVSS4.0

CVE-2025-69426 - Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded SSH Credentials RCE

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY all…

📅 Published: Jan. 9, 2026, 4:15 p.m. 🔄 Last Modified: April 15, 2026, 2:34 p.m.

6.5

CVSS3.1

CVE-2025-46645 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralizatio…

📅 Published: Jan. 9, 2026, 4:14 p.m. 🔄 Last Modified: Feb. 26, 2026, 3:04 p.m.
Total resulsts: 346514
Page 1942 of 34,652
« previous page » next page
Filters