6.9

CVSS4.0

CVE-2026-5322 - AlejandroArciniegas mcp-data-vis MCP server.js request sql injection

A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation leads to sql injection. T…

πŸ“… Published: April 2, 2026, 5:30 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

8.1

CVSS3.1

CVE-2026-4347 - MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir

The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attac…

πŸ“… Published: April 2, 2026, 5:28 a.m. πŸ”„ Last Modified: April 8, 2026, 4:37 p.m.

5.3

CVSS4.0

CVE-2026-5321 - vanna-ai vanna FastAPI/Flask Server cross-domain policy

A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the component FastAPI/Flask Server. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The exploit has been publ…

πŸ“… Published: April 2, 2026, 4:45 a.m. πŸ”„ Last Modified: April 2, 2026, 5:16 a.m.

6.9

CVSS4.0

CVE-2026-5320 - vanna-ai vanna Chat API Endpoint v2 missing authentication

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of the component Chat API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now…

πŸ“… Published: April 2, 2026, 3:45 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-5319 - itsourcecode Payroll Management System navbar.php cross site scripting

A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed…

πŸ“… Published: April 2, 2026, 2:45 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-5318 - LibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. T…

πŸ“… Published: April 2, 2026, 1:45 a.m. πŸ”„ Last Modified: April 7, 2026, 12:16 p.m.

5.3

CVSS4.0

CVE-2026-5317 - Nothings stb stb_vorbis.c start_decoder out-of-bounds write

A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The ve…

πŸ“… Published: April 2, 2026, 12:45 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.4

CVSS3.1

CVE-2026-1243 - IBM Content Navigator is affected by , a Cross-Site Scripting (XSS) vulnerability

IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: April 2, 2026, 12:14 a.m. πŸ”„ Last Modified: April 8, 2026, 7:56 p.m.

5.3

CVSS4.0

CVE-2026-5316 - Nothings stb stb_vorbis.c setup_free allocation of resources

A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation leads to allocation of resources. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor …

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.5

CVSS3.1

CVE-2026-23417 - bpf: Fix constant blinding for PROBE_MEM32 stores

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores BPF_ST | BPF_PROBE_MEM32 immediate stores are not handled by bpf_jit_blind_insn(), allowing user-controlled 32-bit immediates to survive unblinded into JIT-compiled native code wh…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.
Total resulsts: 343968
Page 223 of 34,397
Β« previous page Β» next page
Filters