| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-78337 | Med | 0.24 | — | 0.00 | Aug 24, 2026 | Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG… | ||
| CVE-2026-78245 | Hig | 0.47 | 7.3 | 0.01 | Aug 24, 2026 | A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be… | ||
| CVE-2026-78244 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The… | ||
| CVE-2026-76172 | Hig | 0.42 | 7.5 | 0.00 | Aug 24, 2026 | fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme… | ||
| CVE-2026-59295 | Med | 0.38 | 5.9 | 0.00 | Aug 24, 2026 | It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) condition due to an unbounded memory leak. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18… | ||
| CVE-2026-10618 | Med | 0.35 | 5.4 | 0.00 | Aug 24, 2026 | Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored,… | ||
| CVE-2026-10582 | Hig | 0.48 | 7.4 | 0.00 | Aug 24, 2026 | Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an… | ||
| CVE-2026-78317 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||
| CVE-2026-78316 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||
| CVE-2026-78315 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||
| CVE-2026-78314 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||
| CVE-2026-75975 | Hig | 0.42 | 7.5 | 0.00 | Aug 24, 2026 | fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6… | ||
| CVE-2026-75931 | Hig | 0.42 | 7.5 | 0.00 | Aug 24, 2026 | fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own… | ||
| CVE-2026-75899 | Hig | 0.42 | 7.5 | 0.00 | Aug 24, 2026 | fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different… | ||
| CVE-2026-66897 | Cri | 0.57 | 9.9 | 0.01 | Aug 24, 2026 | A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in… | ||
| CVE-2026-16249 | 0.00 | — | — | Aug 24, 2026 | Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID. | |||
| CVE-2026-78321 | Med | 0.39 | — | 0.00 | Aug 24, 2026 | The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server… | ||
| CVE-2026-78306 | Hig | 0.55 | — | 0.00 | Aug 24, 2026 | DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the… | ||
| CVE-2026-78255 | — | Hig | 0.57 | — | 0.00 | Aug 24, 2026 | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network to enumerate valid filenames… | |
| CVE-2026-77994 | Cri | 0.60 | — | 0.00 | Aug 24, 2026 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model. | ||
| CVE-2026-77993 | Med | 0.34 | — | 0.00 | Aug 24, 2026 | Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter. | ||
| CVE-2026-8173 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2026 | The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network… | ||
| CVE-2026-78202 | Hig | 0.47 | 7.3 | 0.01 | Aug 24, 2026 | A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and… | ||
| CVE-2026-78201 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been… | ||
| CVE-2026-78200 | Med | 0.41 | 6.3 | 0.00 | Aug 24, 2026 | A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published… | ||
| CVE-2026-78199 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The… | ||
| CVE-2026-78198 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be… | ||
| CVE-2026-78197 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated… | ||
| CVE-2026-78196 | Med | 0.22 | 4.4 | 0.00 | Aug 24, 2026 | A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The… | ||
| CVE-2026-78187 | Low | 0.13 | 3.1 | 0.01 | Aug 24, 2026 | A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high complexity level is associated… | ||
| CVE-2026-78186 | Med | 0.21 | 4.3 | 0.01 | Aug 24, 2026 | A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out remotely. The exploit has been… | ||
| CVE-2026-59561 | Hig | 0.51 | 7.8 | 0.01 | Aug 24, 2026 | Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal". | ||
| CVE-2026-78213 | Hig | 0.57 | 8.7 | 0.00 | Aug 24, 2026 | Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content. | ||
| CVE-2026-78212 | Hig | 0.49 | 7.5 | 0.01 | Aug 24, 2026 | 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files. | ||
| CVE-2026-78211 | Cri | 0.64 | 9.8 | 0.02 | Aug 24, 2026 | 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server. | ||
| CVE-2026-78185 | Med | 0.41 | 6.3 | 0.00 | Aug 24, 2026 | A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/cust_edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public… | ||
| CVE-2026-78182 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The… | ||
| CVE-2026-78181 | Hig | 0.47 | 7.3 | 0.01 | Aug 24, 2026 | A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely.… | ||
| CVE-2026-78180 | Hig | 0.47 | 7.3 | 0.01 | Aug 24, 2026 | A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly… | ||
| CVE-2026-78179 | Med | 0.41 | 6.3 | 0.00 | Aug 24, 2026 | A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to… | ||
| CVE-2026-19853 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2026 | NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school. | ||
| CVE-2026-19852 | Med | 0.40 | 6.1 | 0.00 | Aug 24, 2026 | NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting. | ||
| CVE-2026-19200 | Hig | 0.51 | 8.9 | 0.00 | Aug 24, 2026 | The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required… | ||
| CVE-2026-78178 | Hig | 0.47 | 7.3 | 0.01 | Aug 24, 2026 | A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated… | ||
| CVE-2026-78177 | Med | 0.29 | 4.5 | 0.01 | Aug 24, 2026 | A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools Event Bus. The manipulation of the argument packageName… | ||
| CVE-2026-78171 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/processlogin.php. The manipulation of the argument User leads to sql injection. It is possible to initiate the attack… | ||
| CVE-2026-78170 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2026 | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from remote. The exploit has been… | ||
| CVE-2026-78169 | Cri | 0.64 | 9.9 | 0.01 | Aug 24, 2026 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer… | ||
| CVE-2026-78168 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit… | ||
| CVE-2026-78167 | Cri | 0.65 | 10.0 | 0.01 | Aug 24, 2026 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit… |
- risk 0.24cvss —epss 0.00
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG…
- risk 0.47cvss 7.3epss 0.01
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The…
- risk 0.42cvss 7.5epss 0.00
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme…
- risk 0.38cvss 5.9epss 0.00
It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) condition due to an unbounded memory leak. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18…
- risk 0.35cvss 5.4epss 0.00
Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored,…
- risk 0.48cvss 7.4epss 0.00
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an…
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
- risk 0.42cvss 7.5epss 0.00
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6…
- risk 0.42cvss 7.5epss 0.00
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own…
- risk 0.42cvss 7.5epss 0.00
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different…
- risk 0.57cvss 9.9epss 0.01
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in…
- CVE-2026-16249Aug 24, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID.
- risk 0.39cvss —epss 0.00
The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server…
- risk 0.55cvss —epss 0.00
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the…
- risk 0.57cvss —epss 0.00
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network to enumerate valid filenames…
- risk 0.60cvss —epss 0.00
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.
- risk 0.34cvss —epss 0.00
Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.
- risk 0.34cvss 5.3epss 0.00
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network…
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and…
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been…
- risk 0.41cvss 6.3epss 0.00
A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The…
- risk 0.47cvss 7.3epss 0.00
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be…
- risk 0.47cvss 7.3epss 0.00
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated…
- risk 0.22cvss 4.4epss 0.00
A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The…
- risk 0.13cvss 3.1epss 0.01
A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high complexity level is associated…
- risk 0.21cvss 4.3epss 0.01
A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out remotely. The exploit has been…
- risk 0.51cvss 7.8epss 0.01
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
- risk 0.57cvss 8.7epss 0.00
Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.
- risk 0.49cvss 7.5epss 0.01
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.
- risk 0.64cvss 9.8epss 0.02
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.
- risk 0.41cvss 6.3epss 0.00
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/cust_edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public…
- risk 0.47cvss 7.3epss 0.00
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The…
- risk 0.47cvss 7.3epss 0.01
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely.…
- risk 0.47cvss 7.3epss 0.01
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to…
- risk 0.34cvss 5.3epss 0.00
NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.
- risk 0.40cvss 6.1epss 0.00
NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.
- risk 0.51cvss 8.9epss 0.00
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required…
- risk 0.47cvss 7.3epss 0.01
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated…
- risk 0.29cvss 4.5epss 0.01
A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools Event Bus. The manipulation of the argument packageName…
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/processlogin.php. The manipulation of the argument User leads to sql injection. It is possible to initiate the attack…
- risk 0.57cvss 8.8epss 0.01
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from remote. The exploit has been…
- risk 0.64cvss 9.9epss 0.01
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer…
- risk 0.64cvss 9.8epss 0.01
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit…
- risk 0.65cvss 10.0epss 0.01
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit…