5.3

CVSS4.0

CVE-2026-7510 - OWAP DefectDojo Benchmark/Engagement/Product/Survey authorization

A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been publi…

📅 Published: April 30, 2026, 11 p.m. 🔄 Last Modified: April 30, 2026, 11 p.m.

5.3

CVSS4.0

CVE-2026-7508 - Bootstrap CMS Page Creation show.blade.php code injection

A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code injection. Remote exploitation of the attack is possible. T…

📅 Published: April 30, 2026, 10:45 p.m. 🔄 Last Modified: April 30, 2026, 10:45 p.m.

6.9

CVSS4.0

CVE-2026-7506 - SourceCodester Hotel Management System check sql injection

A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/check. Such manipulation of the argument room_type leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the pub…

📅 Published: April 30, 2026, 10:30 p.m. 🔄 Last Modified: April 30, 2026, 10:30 p.m.

6.9

CVSS4.0

CVE-2026-7505 - nextlevelbuilder GoClaw/GoClaw Lite RPC improper authorization

A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.…

📅 Published: April 30, 2026, 10 p.m. 🔄 Last Modified: April 30, 2026, 10 p.m.

0.0

CVE-2026-28909 -

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

📅 Published: April 30, 2026, 10 p.m. 🔄 Last Modified: April 30, 2026, 10 p.m.

6.5

CVSS3.1

CVE-2026-1577 - IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple su…

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.

📅 Published: April 30, 2026, 9:49 p.m. 🔄 Last Modified: April 30, 2026, 9:49 p.m.

6.5

CVSS3.1

CVE-2025-36122 - IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set …

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.

📅 Published: April 30, 2026, 9:48 p.m. 🔄 Last Modified: April 30, 2026, 9:48 p.m.

5.3

CVSS3.1

CVE-2025-14688 - IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific con…

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.

📅 Published: April 30, 2026, 9:48 p.m. 🔄 Last Modified: April 30, 2026, 9:48 p.m.

8.7

CVSS4.0

CVE-2026-7503 - code-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflow

A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument wepkey2 results in buffer overflow. The attack can be lau…

📅 Published: April 30, 2026, 9:45 p.m. 🔄 Last Modified: April 30, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2026-2311 - IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.

📅 Published: April 30, 2026, 9:45 p.m. 🔄 Last Modified: April 30, 2026, 9:45 p.m.
Total resulsts: 347407
Page 5 of 34,741
« previous page » next page
Filters