Low — Podatności CVE o niskim poziomie ważności (CVSS < 4.0). Monitoruj i oceń ryzyko. Znaleziono 200 CVE.

Inne poziomy: 🔴 Critical 🟠 High 🟡 Medium
CVE-2013-2423 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOT…

3.7 CVSS
93.4% EPSS
oracle 2013-04-17
CVE-2006-5614 ⚪ Do wiadomości
appscloud

Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, w…

2.6 CVSS
88.4% EPSS
microsoftdos 2006-10-31
CVE-1999-0532 ⚪ Do wiadomości

A DNS server allows zone transfers.

0.0 CVSS
82.8% EPSS
1997-07-01
CVE-2025-34037 ⚪ Do wiadomości

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied inp…

0.0 CVSS
81.6% EPSS
rce 2025-06-24
CVE-2010-0926 ⚪ Do wiadomości

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, an…

3.5 CVSS
52.4% EPSS
sambapath-traversal 2010-03-10
CVE-2006-5229 ⚪ Do wiadomości

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses t…

2.6 CVSS
56.6% EPSS
novell 2006-10-10
CVE-2006-4685 ⚪ Do wiadomości
appscloud

The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other …

2.6 CVSS
55.4% EPSS
microsoft 2006-10-10
CVE-1999-1453 ⚪ Do wiadomości
appscloud

Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

2.6 CVSS
50.3% EPSS
microsoftexploit 1999-02-02
CVE-1999-1538 ⚪ Do wiadomości
appscloud

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information…

2.1 CVSS
50.3% EPSS
microsoftexploit 1999-01-14
CVE-1999-0487 ⚪ Do wiadomości
appscloud

The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.

2.6 CVSS
22.7% EPSS
microsoft 1999-05-01
CVE-1999-0869 ⚪ Do wiadomości
appscloud

Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.

2.6 CVSS
18.7% EPSS
microsoft 1998-12-01
CVE-2006-4842 ⚪ Do wiadomości

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users t…

3.6 CVSS
12.2% EPSS
netscape 2006-10-12
CVE-2024-51788 ⚪ Do wiadomości

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Sto…

0.0 CVSS
29.6% EPSS
2024-11-11
CVE-2025-26793 ⚪ Do wiadomości

The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change the…

0.0 CVSS
27.2% EPSS
2025-02-15
CVE-2024-52375 ⚪ Do wiadomości

Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative datasets-manager-by-arttia-creative.This issue affects Datasets Manager by Arttia Creative: from n/a th…

0.0 CVSS
25.7% EPSS
2024-11-14
CVE-1999-0612 ⚪ Do wiadomości

A version of finger is running that exposes valid user information to any entity on the network.

0.0 CVSS
25.2% EPSS
gnu 1997-03-01
CVE-2010-0733 ⚪ Do wiadomości
apps

Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with ma…

3.5 CVSS
7.7% EPSS
postgresqldos 2010-03-19
CVE-2006-5432 ⚪ Do wiadomości

Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) em…

2.6 CVSS
11.8% EPSS
CVE-1999-0871 ⚪ Do wiadomości
appscloud

Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.

2.6 CVSS
11.2% EPSS
microsoft 1998-09-04
CVE-1999-0717 ⚪ Do wiadomości
appscloud

A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.

2.6 CVSS
10.2% EPSS
microsoft 1999-05-07
CVE-2010-0716 ⚪ Do wiadomości
appscloud

_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), whi…

3.5 CVSS
4.7% EPSS
microsoftexploitxss 2010-02-26
CVE-1999-0870 ⚪ Do wiadomości
appscloud

Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.

2.6 CVSS
7.2% EPSS
microsoft 1998-10-01
CVE-2010-0801 ⚪ Do wiadomości

Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authenticated users, with "Public Back-end" group permissions, to read arbitrary files via directory trav…

3.5 CVSS
2.2% EPSS
CVE-2026-3632 ⚪ Do wiadomości
os

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP h…

3.9 CVSS
0.1% EPSS
redhatexploitssrf 2026-03-17
CVE-2025-1939 ⚪ Do wiadomości

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actual…

3.9 CVSS
0.1% EPSS
mozilla 2025-03-04
CVE-2020-1968 ⚪ Do wiadomości

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case…

3.7 CVSS
1.0% EPSS
fujitsu 2020-09-09
CVE-2026-3633 ⚪ Do wiadomości
os

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Car…

3.9 CVSS
0.0% EPSS
redhatexploit 2026-03-17
CVE-2026-3634 ⚪ Do wiadomości
os

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_se…

3.9 CVSS
0.0% EPSS
redhatexploit 2026-03-17
CVE-2026-34768 ⚪ Do wiadomości

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true…

3.9 CVSS
0.0% EPSS
electronjs 2026-04-04
CVE-2025-66037 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling …

3.9 CVSS
0.0% EPSS
2026-03-30
CVE-2025-66038 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and val…

3.9 CVSS
0.0% EPSS
2026-03-30
CVE-2022-4031 ⚪ Do wiadomości

The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the…

3.8 CVSS
0.3% EPSS
simple-press 2022-11-29
CVE-2026-3470 ⚪ Do wiadomości
network

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by pro…

3.8 CVSS
0.1% EPSS
sonicwall 2026-03-31
CVE-2023-2434 ⚪ Do wiadomości

The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated…

3.8 CVSS
0.1% EPSS
kylephillips 2023-05-31
CVE-2024-29948 ⚪ Do wiadomości

There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable device, causing a service abnormality.

3.8 CVSS
0.1% EPSS
2024-04-02
CVE-2025-64350 ⚪ Do wiadomości

Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

3.8 CVSS
0.1% EPSS
2025-10-31
CVE-2025-69015 ⚪ Do wiadomości

Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.…

3.8 CVSS
0.1% EPSS
2025-12-30
CVE-2026-32715 ⚪ Do wiadomości

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, w…

3.8 CVSS
0.0% EPSS
mintplexlabsexploit 2026-03-16
CVE-2026-26230 ⚪ Do wiadomości

Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MM…

3.8 CVSS
0.0% EPSS
mattermost 2026-03-16
CVE-2023-42419 ⚪ Do wiadomości

Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & acces…

3.8 CVSS
0.0% EPSS
2024-03-05
CVE-2025-47555 ⚪ Do wiadomości

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.

3.8 CVSS
0.0% EPSS
2026-01-22
CVE-2026-0849 ⚪ Do wiadomości

Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack exec…

3.8 CVSS
0.0% EPSS
2026-03-16
CVE-2022-40696 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.

3.7 CVSS
0.5% EPSS
CVE-2025-49010 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write i…

3.8 CVSS
0.0% EPSS
2026-03-30
CVE-2025-66215 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE i…

3.8 CVSS
0.0% EPSS
2026-03-30
CVE-2025-4945 ⚪ Do wiadomości

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted …

3.7 CVSS
0.3% EPSS
2025-05-19
CVE-2024-10106 ⚪ Do wiadomości

A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.

3.7 CVSS
0.3% EPSS
buffer-overflow 2025-01-09
CVE-2023-37867 ⚪ Do wiadomości

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: fro…

3.7 CVSS
0.2% EPSS
CVE-2006-5883 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir paramete…

3.5 CVSS
1.2% EPSS
cpanelexploitxss 2006-11-14
CVE-2023-3947 ⚪ Do wiadomości

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This…

3.7 CVSS
0.2% EPSS
imdpen 2023-07-26
CVE-2023-28786 ⚪ Do wiadomości

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Protection.This issue affects Solid Security – Password, Two Factor Authe…

3.7 CVSS
0.2% EPSS
solidwp 2023-12-29
CVE-2017-6052 ⚪ Do wiadomości

A Man-in-the-Middle issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. Communication channel endpoints are not verified, which may allow a remote attacker to access or influence communications betwe…

3.7 CVSS
0.2% EPSS
hyundai 2017-04-26
CVE-2023-40160 ⚪ Do wiadomości

Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary f…

3.7 CVSS
0.2% EPSS
path-traversal 2024-03-18
CVE-2024-43944 ⚪ Do wiadomości

Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation allows Identity Spoofing.This issue affects Maintenance & Coming Soon Re…

3.7 CVSS
0.1% EPSS
auth-bypass 2024-08-29
CVE-2024-3735 ⚪ Do wiadomości

A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown function of the file Main.aspx. The manipulation of the argument New Password/Confirm Password with …

3.7 CVSS
0.1% EPSS
2024-04-13
CVE-2024-2355 ⚪ Do wiadomości

A vulnerability has been found in keerti1924 Secret-Coder-PHP-Project 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /secret_coder.sql. The manipulation leads to…

3.7 CVSS
0.1% EPSS
2024-03-10
CVE-2026-3184 ⚪ Do wiadomości

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could…

3.7 CVSS
0.1% EPSS
kernel 2026-04-03
CVE-2020-8284 ⚪ Do wiadomości
os

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherw…

3.7 CVSS
0.1% EPSS
apple 2020-12-14
CVE-2000-1246 ⚪ Do wiadomości

NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command.

3.5 CVSS
1.1% EPSS
novelldos 2010-04-05
CVE-2026-5123 ⚪ Do wiadomości

A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack m…

3.7 CVSS
0.1% EPSS
osrg 2026-03-30
CVE-2026-32690 ⚪ Do wiadomości
apps

Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sens…

3.7 CVSS
0.1% EPSS
apache 2026-04-18
CVE-2006-4393 ⚪ Do wiadomości
os

Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switching is enabled, allows local users to gain access to Kerberos tickets of other users.

3.7 CVSS
0.1% EPSS
apple 2006-10-03
CVE-2006-5453 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script o…

3.5 CVSS
1.1% EPSS
mozillaxss 2006-10-23
CVE-2026-0988 ⚪ Do wiadomości

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are prov…

3.7 CVSS
0.1% EPSS
buffer-overflowdos 2026-01-21
CVE-2026-32897 ⚪ Do wiadomości

OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset, creating dual-us…

3.7 CVSS
0.1% EPSS
openclaw 2026-03-21
CVE-2026-4831 ⚪ Do wiadomości

A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Perf…

3.7 CVSS
0.1% EPSS
2026-03-26
CVE-2026-5360 ⚪ Do wiadomości

A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is character…

3.7 CVSS
0.1% EPSS
free5gc 2026-04-02
CVE-1999-0123 ⚪ Do wiadomości

Race condition in Linux mailx command allows local users to read user files.

3.7 CVSS
0.1% EPSS
slackware 1995-12-01
CVE-1999-0401 ⚪ Do wiadomości
os

A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.

3.7 CVSS
0.1% EPSS
linux 1999-01-01
CVE-2026-4988 ⚪ Do wiadomości

A security flaw has been discovered in Open5GS 2.7.6. This issue affects the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6b of the component CCA Message Handler. The manipulation results in denial of service. The attack ma…

3.7 CVSS
0.1% EPSS
open5gsdosexploit 2026-03-27
CVE-2024-45453 ⚪ Do wiadomości

Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect jf3-maintenance-mode.This issue affects Maintenance Redirect: from n/a through <= 2.0.1.

3.7 CVSS
0.1% EPSS
auth-bypass 2024-09-23
CVE-2023-2897 ⚪ Do wiadomości

The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP heade…

3.7 CVSS
0.1% EPSS
brizy 2023-06-09
CVE-2026-40184 ⚪ Do wiadomości

TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2.

3.7 CVSS
0.1% EPSS
mauriceboe 2026-04-10
CVE-1999-0141 ⚪ Do wiadomości

Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.

3.7 CVSS
0.1% EPSS
netscape 1996-03-29
CVE-2025-52623 ⚪ Do wiadomości

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials,…

3.7 CVSS
0.1% EPSS
hcltech 2026-02-03
CVE-2026-40969 ⚪ Do wiadomości
cloud

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure…

3.7 CVSS
0.1% EPSS
vmware 2026-04-28
CVE-2026-22204 ⚪ Do wiadomości

wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a maliciou…

3.7 CVSS
0.1% EPSS
gvectors 2026-03-13
CVE-2026-5124 ⚪ Do wiadomości

A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Handler. The manipulation leads to im…

3.7 CVSS
0.1% EPSS
osrg 2026-03-30
CVE-2026-21388 ⚪ Do wiadomości

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversi…

3.7 CVSS
0.1% EPSS
mattermostdos 2026-04-09
CVE-2026-24661 ⚪ Do wiadomości

Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversi…

3.7 CVSS
0.1% EPSS
mattermostdos 2026-04-09
CVE-2024-31265 ⚪ Do wiadomości

Cross-Site Request Forgery (CSRF) vulnerability in SumoMe Sumo.This issue affects Sumo: from n/a through 1.34.

3.7 CVSS
0.1% EPSS
2024-04-12
CVE-2026-22018 ⚪ Do wiadomości
appsos

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50,…

3.7 CVSS
0.1% EPSS
oracledos 2026-04-21
CVE-2026-41354 ⚪ Do wiadomości

OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or senders to collide. Attackers can exploit weak dedupl…

3.7 CVSS
0.1% EPSS
openclaw 2026-04-23
CVE-2025-71264 ⚪ Do wiadomości

Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).

3.7 CVSS
0.0% EPSS
dos 2026-03-16
CVE-2026-33070 ⚪ Do wiadomości

FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnerability in the deleteShareLink endpoint allows any unauthenticated user to delete arbitrary file shar…

3.7 CVSS
0.0% EPSS
filerisedosexploit 2026-03-20
CVE-2026-4633 ⚪ Do wiadomości

A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existenc…

3.7 CVSS
0.0% EPSS
2026-03-23
CVE-2026-4588 ⚪ Do wiadomości

A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-level API key Handler. …

3.7 CVSS
0.0% EPSS
2026-03-23
CVE-2026-5122 ⚪ Do wiadomości

A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Handler. Performing a manipulation of the argum…

3.7 CVSS
0.0% EPSS
osrg 2026-03-30
CVE-2025-67806 ⚪ Do wiadomości

The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this…

3.7 CVSS
0.0% EPSS
sagedpw 2026-04-01
CVE-2026-26961 ⚪ Do wiadomości

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expression. When a Content…

3.7 CVSS
0.0% EPSS
rack 2026-04-02
CVE-2026-5413 ⚪ Do wiadomości

A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argument connectionDetails…

3.7 CVSS
0.0% EPSS
2026-04-02
CVE-2026-35537 ⚪ Do wiadomości

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted ses…

3.7 CVSS
0.0% EPSS
CVE-2026-35448 ⚪ Do wiadomości

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint …

3.7 CVSS
0.0% EPSS
wwbnexploit 2026-04-06
CVE-2026-34166 ⚪ Do wiadomości

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charge…

3.7 CVSS
0.0% EPSS
liquidjsdosexploit 2026-04-08
CVE-2026-40097 ⚪ Do wiadomości

Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted a…

3.7 CVSS
0.0% EPSS
smallstep 2026-04-10
CVE-2025-52629 ⚪ Do wiadomości

HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by allowing unsafe scripts or resources to ex…

3.7 CVSS
0.0% EPSS
hcltechxss 2026-02-03
CVE-2025-52631 ⚪ Do wiadomości

HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgr…

3.7 CVSS
0.0% EPSS
hcltech 2026-02-03
CVE-2026-32293 ⚪ Do wiadomości

The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this connection, allowing an attacker-in-the-middle to se…

3.7 CVSS
0.0% EPSS
gl-inet 2026-03-17
CVE-2026-31991 ⚪ Do wiadomości

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy incorrectly accepts sender identities from DM pairing-store approvals. Attackers can exploit this bou…

3.7 CVSS
0.0% EPSS
openclaw 2026-03-19
CVE-2026-32050 ⚪ Do wiadomości

OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized senders to enqueue status events before authorization checks are applied. Att…

3.7 CVSS
0.0% EPSS
openclaw 2026-03-21
CVE-2026-32067 ⚪ Do wiadomości

OpenClaw versions prior to 2026.2.26 contains an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple a…

3.7 CVSS
0.0% EPSS
openclaw 2026-03-21
CVE-2026-4587 ⚪ Do wiadomości

A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument curlOptions results in i…

3.7 CVSS
0.0% EPSS
2026-03-23
CVE-2025-55275 ⚪ Do wiadomości

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user.

3.7 CVSS
0.0% EPSS
hcltech 2026-03-26
CVE-2026-33490 ⚪ Do wiadomości

H3 is a minimal H(TTP) framework. In versions 2.0.0-0 through 2.0.1-rc.16, the `mount()` method in h3 uses a simple `startsWith()` check to determine whether incoming requests fall under a mounted sub-application's path …

3.7 CVSS
0.0% EPSS
h3exploit 2026-03-26
CVE-2026-5622 ⚪ Do wiadomości

A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. Thi…

3.7 CVSS
0.0% EPSS
2026-04-06
CVE-2026-35648 ⚪ Do wiadomości

OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when delivered. Attackers can exploit stale allowlists or declarations that su…

3.7 CVSS
0.0% EPSS
2026-04-10
CVE-2026-40263 ⚪ Do wiadomości

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt password verification only when the supplied username exists, returning immediately for nonexistent us…

3.7 CVSS
0.0% EPSS
2026-04-17
CVE-2026-6610 ⚪ Do wiadomości

A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument …

3.7 CVSS
0.0% EPSS
2026-04-20
CVE-2025-52625 ⚪ Do wiadomości

A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or brows…

3.7 CVSS
0.0% EPSS
hcltech 2025-10-10
CVE-2025-52630 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

3.7 CVSS
0.0% EPSS
hcltech 2025-10-10
CVE-2025-52634 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

3.7 CVSS
0.0% EPSS
hcltech 2025-10-10
CVE-2025-52635 ⚪ Do wiadomości

A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

3.7 CVSS
0.0% EPSS
hcltech 2025-10-10
CVE-2026-26013 ⚪ Do wiadomości

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token …

3.7 CVSS
0.0% EPSS
langchainssrf 2026-02-10
CVE-2025-13718 ⚪ Do wiadomości

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by una…

3.7 CVSS
0.0% EPSS
ibm 2026-03-13
CVE-2026-28753 ⚪ Do wiadomości
network

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary …

3.7 CVSS
0.0% EPSS
f5 2026-03-24
CVE-2026-27860 ⚪ Do wiadomości

If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out au…

3.7 CVSS
0.0% EPSS
dovecot 2026-03-27
CVE-2026-5682 ⚪ Do wiadomości

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptogra…

3.7 CVSS
0.0% EPSS
2026-04-06
CVE-2026-0989 ⚪ Do wiadomości

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially c…

3.7 CVSS
0.0% EPSS
2026-01-15
CVE-2025-40745 ⚪ Do wiadomości

A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602),…

3.7 CVSS
0.0% EPSS
2026-04-14
CVE-2026-33877 ⚪ Do wiadomości

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/reset-request) that al…

3.7 CVSS
0.0% EPSS
CVE-2026-3706 ⚪ Do wiadomości

A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographi…

3.7 CVSS
0.0% EPSS
2026-03-08
CVE-2026-32595 ⚪ Do wiadomości

Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 comtain BasicAuth middleware that allows username enumeration via a timing attack. When a submitt…

3.7 CVSS
0.0% EPSS
traefik 2026-03-20
CVE-2026-4115 ⚪ Do wiadomości

A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographi…

3.7 CVSS
0.0% EPSS
puttyexploit 2026-03-22
CVE-2026-4363 ⚪ Do wiadomości
dev

GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unau…

3.7 CVSS
0.0% EPSS
gitlab 2026-03-25
CVE-2026-37977 ⚪ Do wiadomości
os

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp`…

3.7 CVSS
0.0% EPSS
redhat 2026-04-06
CVE-2026-40194 ⚪ Do wiadomości

phpseclib is a PHP secure communications library. Prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed HMA…

3.7 CVSS
0.0% EPSS
phpseclib 2026-04-10
CVE-2026-33597 ⚪ Do wiadomości

PRSD detection denial of service

3.7 CVSS
0.0% EPSS
powerdnsdos 2026-04-22
CVE-2026-6986 ⚪ Do wiadomości

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulati…

3.7 CVSS
0.0% EPSS
cesantaexploit 2026-04-25
CVE-2024-52380 ⚪ Do wiadomości

Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web Shell to a Web Server.This issue affects Picsmize: from n/a through <= 1.0.0.

0.0 CVSS
18.4% EPSS
2024-11-14
CVE-1999-1498 ⚪ Do wiadomości

Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.

3.6 CVSS
0.4% EPSS
slackwareexploit 1998-04-06
CVE-1999-1224 ⚪ Do wiadomości

IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may c…

3.6 CVSS
0.2% EPSS
CVE-2006-5163 ⚪ Do wiadomości

IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.

3.6 CVSS
0.1% EPSS
ibmexploit 2006-10-05
CVE-2006-5213 ⚪ Do wiadomości

Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregation (network device aggregation).

3.6 CVSS
0.1% EPSS
sun 2006-10-10
CVE-2006-5406 ⚪ Do wiadomości

Passgo Defender 5.2 creates the application directory with insecure permissions (Everyone/Full Control), which allows local users to read and modify sensitive files. NOTE: the provenance of this information is unknown; …

3.6 CVSS
0.1% EPSS
passgo 2006-10-19
CVE-2010-0828 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticated users to inject arbitrary web script or HTML by creating a page with a craf…

3.5 CVSS
0.6% EPSS
moinmoexploitxss 2010-04-05
CVE-2026-32018 ⚪ Do wiadomości

OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-m…

3.6 CVSS
0.0% EPSS
openclaw 2026-03-19
CVE-2026-31863 ⚪ Do wiadomości

Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is f…

3.6 CVSS
0.0% EPSS
anytype 2026-03-11
CVE-2026-24509 ⚪ Do wiadomości

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to De…

3.6 CVSS
0.0% EPSS
delldos 2026-03-11
CVE-2026-32722 ⚪ Do wiadomości

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-contr…

3.6 CVSS
0.0% EPSS
bloombergexploit 2026-03-18
CVE-2026-35386 ⚪ Do wiadomości

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-defa…

3.6 CVSS
0.0% EPSS
openbsd 2026-04-02
CVE-2026-0995 ⚪ Do wiadomości

An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesses related to SME.

3.6 CVSS
0.0% EPSS
arm 2026-03-02
CVE-2023-6160 ⚪ Do wiadomości

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 via the maybe_serve_export function. This makes it possible for authent…

3.3 CVSS
1.5% EPSS
CVE-2003-1582 ⚪ Do wiadomości
appscloud

Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted…

2.6 CVSS
5.0% EPSS
microsoftexploitxss 2010-02-05
CVE-2023-41695 ⚪ Do wiadomości

Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.1.0.

3.5 CVSS
0.4% EPSS
analytify 2024-12-13
CVE-1999-0159 ⚪ Do wiadomości
network

Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.

3.5 CVSS
0.4% EPSS
cisco 1998-08-12
CVE-2010-0684 ⚪ Do wiadomości
apps

Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue ac…

3.5 CVSS
0.4% EPSS
apacheexploitxss 2010-04-05
CVE-2010-0460 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and …

3.5 CVSS
0.3% EPSS
kayakoexploitxss 2010-01-28
CVE-2020-24588 ⚪ Do wiadomości
network

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices …

3.5 CVSS
0.3% EPSS
ciscoexploit 2021-05-11
CVE-2010-1107 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a "custom block t…

3.5 CVSS
0.3% EPSS
fourkitchensxss 2010-03-25
CVE-2010-0370 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in the Node Blocks module 5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal, allows remote authenticated users, with permissions to create or edit content and admi…

3.5 CVSS
0.2% EPSS
CVE-2013-3943 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the…

3.5 CVSS
0.2% EPSS
dnnsoftwarexss 2014-03-12
CVE-2010-1108 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web …

3.5 CVSS
0.2% EPSS
CVE-2010-0606 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message …

3.5 CVSS
0.2% EPSS
osticketexploitxss 2010-02-11
CVE-2010-0697 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inj…

3.5 CVSS
0.2% EPSS
ilya_ivanchenkoxss 2010-02-23
CVE-2024-3138 ⚪ Do wiadomości

** DISPUTED ** A vulnerability was found in francoisjacquet RosarioSIS 11.5.1. It has been rated as problematic. This issue affects some unknown processing of the component Add Portal Note. The manipulation leads to cros…

3.5 CVSS
0.2% EPSS
xss 2024-04-01
CVE-2006-5511 ⚪ Do wiadomości

Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script, HTML, or PHP via the contents parameter, whose …

2.6 CVSS
4.7% EPSS
jaxultrabbexploit 2006-10-25
CVE-2023-2076 ⚪ Do wiadomości

A vulnerability classified as problematic was found in Campcodes Online Traffic Offense Management System 1.0. This vulnerability affects unknown code of the file /classes/Users.phpp. The manipulation of the argument id …

3.5 CVSS
0.1% EPSS
campcodesexploitxss 2023-04-14
CVE-2023-2055 ⚪ Do wiadomości

A vulnerability has been found in Campcodes Advanced Online Voting System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/config_save.php. The manipulation of the argument ti…

3.5 CVSS
0.1% EPSS
campcodesexploitxss 2023-04-14
CVE-2025-55270 ⚪ Do wiadomości

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc.

3.5 CVSS
0.1% EPSS
CVE-2014-125110 ⚪ Do wiadomości

A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback of the file lib/wfu_ajaxactions.php.…

3.5 CVSS
0.1% EPSS
xss 2024-04-01
CVE-2022-4966 ⚪ Do wiadomości

A vulnerability was found in sequentech admin-console up to 6.1.7 and classified as problematic. Affected by this issue is some unknown functionality of the component Election Description Handler. The manipulation leads …

3.5 CVSS
0.1% EPSS
xss 2024-04-01
CVE-2023-2077 ⚪ Do wiadomości

A vulnerability, which was classified as problematic, has been found in Campcodes Online Traffic Offense Management System 1.0. This issue affects some unknown processing of the file /admin/offenses/view_details.php. The…

3.5 CVSS
0.1% EPSS
campcodesexploitxss 2023-04-14
CVE-2024-1979 ⚪ Do wiadomości

A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.

3.5 CVSS
0.1% EPSS
2024-03-13
CVE-2024-2479 ⚪ Do wiadomości

A vulnerability classified as problematic has been found in MHA Sistemas arMHAzena 9.6.0.0. This affects an unknown part of the component Cadastro Page. The manipulation of the argument Query leads to cross site scriptin…

3.5 CVSS
0.1% EPSS
xss 2024-03-15
CVE-2015-10131 ⚪ Do wiadomości

A vulnerability was found in chrisy TFO Graphviz Plugin up to 1.9 on WordPress and classified as problematic. Affected by this issue is the function admin_page_load/admin_page of the file tfo-graphviz-admin.php. The mani…

3.5 CVSS
0.1% EPSS
xss 2024-03-31
CVE-2006-4808 ⚪ Do wiadomości

Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted…

2.6 CVSS
4.6% EPSS
CVE-2024-3687 ⚪ Do wiadomości

A vulnerability was found in bihell Dice 3.1.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The att…

3.5 CVSS
0.1% EPSS
xss 2024-04-12
CVE-2025-55249 ⚪ Do wiadomości

HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-base…

3.5 CVSS
0.1% EPSS
hcltech 2026-01-19
CVE-2020-36826 ⚪ Do wiadomości

A vulnerability was found in AwesomestCode LiveBot. It has been classified as problematic. Affected is the function parseSend of the file js/parseMessage.js. The manipulation leads to cross site scripting. It is possible…

3.5 CVSS
0.1% EPSS
xss 2024-03-25
CVE-2017-20191 ⚪ Do wiadomości

A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. This affects the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js of the comp…

3.5 CVSS
0.1% EPSS
xss 2024-03-31
CVE-2020-36828 ⚪ Do wiadomości

A vulnerability was found in DiscuzX up to 3.4-20200818. It has been classified as problematic. Affected is the function show_next_step of the file upload/install/include/install_function.php. The manipulation of the arg…

3.5 CVSS
0.1% EPSS
xss 2024-03-31
CVE-2014-125111 ⚪ Do wiadomości

A vulnerability was found in namithjawahar Wp-Insert up to 2.0.8 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be laun…

3.5 CVSS
0.1% EPSS
xss 2024-04-08
CVE-2026-32984 ⚪ Do wiadomości

Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a…

3.5 CVSS
0.1% EPSS
CVE-2026-40077 ⚪ Do wiadomości

Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied system ID and proceed without further checks that the user should have access to that system. As a resu…

3.5 CVSS
0.1% EPSS
beszelexploit 2026-04-09
CVE-2026-33659 ⚪ Do wiadomości

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SSRF) via a DNS rebindi…

3.5 CVSS
0.1% EPSS
CVE-2026-24048 ⚪ Do wiadomości

Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1…

3.5 CVSS
0.0% EPSS
linuxfoundationssrf 2026-01-21
CVE-2026-4354 ⚪ Do wiadomości

A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 of the file apply_sec.cgi of the component Web Interface. Such manipulation of the argument Language…

3.5 CVSS
0.0% EPSS
xss 2026-03-18
CVE-2026-4355 ⚪ Do wiadomości

A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of the argument Name res…

3.5 CVSS
0.0% EPSS
xss 2026-03-18
CVE-2026-4494 ⚪ Do wiadomości

A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/pybbs/controller/api/TopicApiController.java. The manipulation leads to cross site scripting. It is …

3.5 CVSS
0.0% EPSS
xss 2026-03-20
CVE-2026-4495 ⚪ Do wiadomości

A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/yiiu/pybbs/controller/api/CommentApiController.java. The manipulation results in cross site scriptin…

3.5 CVSS
0.0% EPSS
xss 2026-03-20
CVE-2026-33422 ⚪ Do wiadomości

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `ip_address` of a flagged user is exposed to any user who can access the review queue, including users wh…

3.5 CVSS
0.0% EPSS
discourse 2026-03-20
CVE-2026-4596 ⚪ Do wiadomości

A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. The manipulation of the argument first_Name leads to cross site scripting…

3.5 CVSS
0.0% EPSS
CVE-2026-4626 ⚪ Do wiadomości

A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The manipulation of the argument Description leads to cross site scripting. …

3.5 CVSS
0.0% EPSS
xss 2026-03-24
CVE-2026-4835 ⚪ Do wiadomości

A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of…

3.5 CVSS
0.0% EPSS
xss 2026-03-26
CVE-2026-4969 ⚪ Do wiadomości

A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads…

3.5 CVSS
0.0% EPSS
xss 2026-03-27
CVE-2026-4973 ⚪ Do wiadomości

A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulation of the argument qui…

3.5 CVSS
0.0% EPSS
xss 2026-03-27
CVE-2026-4991 ⚪ Do wiadomości

A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation …

3.5 CVSS
0.0% EPSS
xss 2026-03-27
CVE-2026-4994 ⚪ Do wiadomości

A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the file backend/openui/server.py of the component APIStatusError Handler. The manipulation of the argum…

3.5 CVSS
0.0% EPSS
2026-03-28
CVE-2026-4995 ⚪ Do wiadomości

A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of the file frontend/public/annotator/index.html of the component Window Message Event Handler. This ma…

3.5 CVSS
0.0% EPSS
xss 2026-03-28
CVE-2026-5325 ⚪ Do wiadomości

A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create Ticket. This manipula…

3.5 CVSS
0.0% EPSS
xss 2026-04-02
CVE-2026-5332 ⚪ Do wiadomości

A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Rem…

3.5 CVSS
0.0% EPSS
xiaopixss 2026-04-02
CVE-2026-5370 ⚪ Do wiadomości

A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module…

3.5 CVSS
0.0% EPSS
xss 2026-04-02
CVE-2026-5468 ⚪ Do wiadomości

A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The…

3.5 CVSS
0.0% EPSS
casbinxss 2026-04-03
CVE-2026-35400 ⚪ Do wiadomości

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, an endpoint in the p…

3.5 CVSS
0.0% EPSS
mcgill 2026-04-08
CVE-2026-5806 ⚪ Do wiadomości

A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cross site scripting. Th…

3.5 CVSS
0.0% EPSS
xss 2026-04-08
CVE-2026-5810 ⚪ Do wiadomości

A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argument ID causes cross si…

3.5 CVSS
0.0% EPSS
xss 2026-04-08
CVE-2026-6107 ⚪ Do wiadomości

A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/common/middleware/chat_headers_middleware.py of the component ChatHeadersMiddleware. This manipulation of…

3.5 CVSS
0.0% EPSS
xss 2026-04-12
CVE-2026-6593 ⚪ Do wiadomości

A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cross site scripting. The…

3.5 CVSS
0.0% EPSS
xss 2026-04-20
CVE-2026-6600 ⚪ Do wiadomości

A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of the component Fronten…

3.5 CVSS
0.0% EPSS
xss 2026-04-20
CVE-2024-7083 ⚪ Do wiadomości

The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilt…

3.5 CVSS
0.0% EPSS
xss 2026-04-20