6.1

CVSS3.1

CVE-2026-33403 - Pi-hole has a Reflected XSS / HTML injection in taillog.js

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, a reflected DOM-based XSS vulnerability in taillog.js allows an unauthenticated attacker to inject arbitrary HTML into the Pi-hole admin interface b…

πŸ“… Published: April 6, 2026, 2:48 p.m. πŸ”„ Last Modified: April 13, 2026, 2:27 p.m.

8.5

CVSS3.1

CVE-2026-34885 - WordPress Media LIbrary Assistant plugin <= 3.34 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34.

πŸ“… Published: April 6, 2026, 2:47 p.m. πŸ”„ Last Modified: April 24, 2026, 6:08 p.m.

4.2

CVSS3.1

CVE-2026-32602 - Homarr has a Race Condition in Invite Token Registration (TOCTOU)

Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create multiple user accounts from a single-use invite token. The registration flow performs three sequential database operation…

πŸ“… Published: April 6, 2026, 2:42 p.m. πŸ”„ Last Modified: April 13, 2026, 2:27 p.m.

7.2

CVSS3.1

CVE-2026-29047 - GLPI has an Authenticated SQL Injection via log exports

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

πŸ“… Published: April 6, 2026, 2:39 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

8.1

CVSS3.1

CVE-2026-26263 - GLPI has an Unauthenticated SQL Injection via Search engine

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

πŸ“… Published: April 6, 2026, 2:36 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

7.5

CVSS3.1

CVE-2026-26027 - GLPI has an Unauthenticated Stored XSS via inventory

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

πŸ“… Published: April 6, 2026, 2:35 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

9.1

CVSS3.1

CVE-2026-26026 - GLPI has a Server-Side Template Injection via Double-Compilation

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

πŸ“… Published: April 6, 2026, 2:33 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

7.2

CVSS3.1

CVE-2026-25932 - GLPI has Stored XSS in Supplier 'Website' field

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

πŸ“… Published: April 6, 2026, 2:31 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

6.9

CVSS4.0

CVE-2026-5663 - OFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injection

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. T…

πŸ“… Published: April 6, 2026, 2:15 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.

6.9

CVSS4.0

CVE-2026-5661 - Free5GC NGSetupRequest denial of service

A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit is publicly available and might be used.

πŸ“… Published: April 6, 2026, 2:08 p.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 349182
Page 668 of 34,919
Β« previous page Β» next page
Filters