5.3

CVSS4.0

CVE-2026-6202 - code-projects Easy Blog Site post.php sql injection

A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used …

πŸ“… Published: April 13, 2026, 7:15 p.m. πŸ”„ Last Modified: April 22, 2026, 8:23 p.m.

5.3

CVSS4.0

CVE-2026-6201 - CodeAstro Online Job Portal Delete Job Posting job-delete.php access control

A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. T…

πŸ“… Published: April 13, 2026, 7 p.m. πŸ”„ Last Modified: April 22, 2026, 8:23 p.m.

7.5

CVSS3.1

CVE-2026-32605 - Nimiq: Remote crash via off-by-one signer bounds check in proposal buffer

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an untrusted peer could crash a validator by publishing a signed tendermint proposal message where signer == validators.num_validators(). Proposa…

πŸ“… Published: April 13, 2026, 6:54 p.m. πŸ”„ Last Modified: April 24, 2026, 5:11 p.m.

8.7

CVSS4.0

CVE-2026-6200 - Tenda F456 webtypelibrary formwebtypelibrary stack-based overflow

A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the file /goform/webtypelibrary. This manipulation of the argument menufacturer/Go causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly…

πŸ“… Published: April 13, 2026, 6:45 p.m. πŸ”„ Last Modified: April 14, 2026, 4:33 p.m.

8.7

CVSS4.0

CVE-2026-6199 - Tenda F456 qossetting fromqossetting stack-based overflow

A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

πŸ“… Published: April 13, 2026, 6:30 p.m. πŸ”„ Last Modified: April 14, 2026, 4:33 p.m.

8.7

CVSS4.0

CVE-2026-6198 - Tenda F456 NatStaticSetting fromNatStaticSetting stack-based overflow

A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed…

πŸ“… Published: April 13, 2026, 6:15 p.m. πŸ”„ Last Modified: April 14, 2026, 4:33 p.m.

9.3

CVSS4.0

CVE-2026-40044 - Pachno 1.0.6 FileCache Deserialization Remote Code Execution

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files with predictable names in the cache directory, whic…

πŸ“… Published: April 13, 2026, 6:11 p.m. πŸ”„ Last Modified: April 17, 2026, 3:28 p.m.

7.1

CVSS4.0

CVE-2026-40043 - Pachno 1.0.6 Authentication Bypass via runSwitchUser()

Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate privileges by manipulating the original_username cookie. Attackers can set the client-controlled original_username cookie to any value and request a s…

πŸ“… Published: April 13, 2026, 6:11 p.m. πŸ”„ Last Modified: April 17, 2026, 3:28 p.m.

9.3

CVSS4.0

CVE-2026-40042 - Pachno 1.0.6 Wiki TextParser XML External Entity Injection

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, …

πŸ“… Published: April 13, 2026, 6:10 p.m. πŸ”„ Last Modified: April 17, 2026, 3:28 p.m.

5.3

CVSS4.0

CVE-2026-40041 - Pachno 1.0.6 Cross-Site Request Forgery via State-Changing Endpoints

Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in authenticated user context by exploiting missing CSRF protections on state-changing endpoints. Attackers can craft malicious requests targeting login, registration, file upload, mi…

πŸ“… Published: April 13, 2026, 6:10 p.m. πŸ”„ Last Modified: April 17, 2026, 3:28 p.m.
Total resulsts: 347814
Page 361 of 34,782
Β« previous page Β» next page
Filters