6.9

CVSS4.0

CVE-2026-0583 - code-projects Online Product Reservation System User Login login.php sql injection

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/user/login.php of the component User Login. The manipulation of the argument emailadd results in sql injection. The attack may be launched remotely. Th…

📅 Published: Jan. 5, 2026, 9:02 a.m. 🔄 Last Modified: April 18, 2026, 8:30 a.m.

8.8

CVSS4.0

CVE-2025-66518 - Apache Kyuubi: Unauthorized directory access due to missing path normalization

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade t…

📅 Published: Jan. 5, 2026, 8:46 a.m. 🔄 Last Modified: Jan. 27, 2026, 9:32 p.m.

5.3

CVSS4.0

CVE-2026-0582 - itsourcecode Society Management System edit_activity_query.php sql injection

A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_activity_query.php. The manipulation of the argument Title leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be …

📅 Published: Jan. 5, 2026, 8:32 a.m. 🔄 Last Modified: April 18, 2026, 7:30 p.m.

8.7

CVSS4.0

CVE-2025-15240 - Quanta Computer|QOCA aim AI Medical Cloud Platform - Arbitrary File Upload

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

📅 Published: Jan. 5, 2026, 8:18 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:10 p.m.

7.1

CVSS4.0

CVE-2025-15239 - Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Jan. 5, 2026, 8:10 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:09 p.m.

5.3

CVSS4.0

CVE-2026-0581 - Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection

A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be …

📅 Published: Jan. 5, 2026, 8:02 a.m. 🔄 Last Modified: April 18, 2026, 8:30 a.m.

7.1

CVSS4.0

CVE-2025-15238 - Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Jan. 5, 2026, 8 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:09 p.m.

4.8

CVSS4.0

CVE-2025-15022 - Cross-site scripting in Action caption

Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS) if caption content is derived from user input. In Vaadin Framework 7 and 8, the Action class is a general-purpose class that may be used by multiple components. The fixed versio…

📅 Published: Jan. 5, 2026, 7:52 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-15237 - Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.

📅 Published: Jan. 5, 2026, 7:42 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:14 p.m.

5.3

CVSS4.0

CVE-2025-15236 - Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.

📅 Published: Jan. 5, 2026, 7:38 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:15 p.m.
Total resulsts: 347438
Page 2117 of 34,744
« previous page » next page
Filters