6.9

CVSS4.0

CVE-2026-6187 - SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=chk_prod_availability. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit i…

πŸ“… Published: April 13, 2026, 3:30 p.m. πŸ”„ Last Modified: April 22, 2026, 8:23 p.m.

8.7

CVSS4.0

CVE-2026-6186 - UTT HiPER 1200GW formNatStaticMap strcpy buffer overflow

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the function strcpy of the file /goform/formNatStaticMap. The manipulation of the argument NatBind leads to buffer overflow. The attack is possible to be carried out remotely. The exploit h…

πŸ“… Published: April 13, 2026, 3:15 p.m. πŸ”„ Last Modified: April 14, 2026, 7:37 p.m.

4.8

CVSS4.0

CVE-2026-6184 - code-projects Simple Content Management System welcome.php cross site scripting

A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Title can lead to cross site scripting. The attack can be executed remotely. The exploit has been made…

πŸ“… Published: April 13, 2026, 3 p.m. πŸ”„ Last Modified: April 22, 2026, 8:23 p.m.

7.8

CVSS3.1

CVE-2026-1462 - Safe Mode Bypass in keras-team/keras

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-…

πŸ“… Published: April 13, 2026, 2:55 p.m. πŸ”„ Last Modified: April 17, 2026, 3:34 p.m.

6.9

CVSS4.0

CVE-2026-6183 - code-projects Simple Content Management System index.php sql injection

A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is some unknown functionality of the file /web/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The explo…

πŸ“… Published: April 13, 2026, 2:45 p.m. πŸ”„ Last Modified: April 22, 2026, 8:23 p.m.

8.8

CVSS3.1

CVE-2026-33858 - Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom …

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, wh…

πŸ“… Published: April 13, 2026, 2:36 p.m. πŸ”„ Last Modified: April 17, 2026, 6:40 p.m.

6.9

CVSS4.0

CVE-2026-6182 - code-projects Simple Content Management System login.php sql injection

A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /web/admin/login.php. Such manipulation of the argument User leads to sql injection. The attack may be launched remotely. The exploit is publi…

πŸ“… Published: April 13, 2026, 2:30 p.m. πŸ”„ Last Modified: April 22, 2026, 8:23 p.m.

7.5

CVSS3.1

CVE-2025-66236 - Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not clear or explicit enough, even though Airf…

πŸ“… Published: April 13, 2026, 2:20 p.m. πŸ”„ Last Modified: April 17, 2026, 6:41 p.m.

0.0

CVE-2026-6221 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: April 13, 2026, 1:34 p.m. πŸ”„ Last Modified: April 29, 2026, 10:19 p.m.

7.1

CVSS3.1

CVE-2026-34476 - Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server

Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.

πŸ“… Published: April 13, 2026, 1:01 p.m. πŸ”„ Last Modified: April 14, 2026, 4:34 p.m.
Total resulsts: 347988
Page 382 of 34,799
Β« previous page Β» next page
Filters