| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66369 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly,… | ||
| CVE-2026-66364 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length,… | ||
| CVE-2026-66360 | Hig | 0.49 | 7.5 | 0.00 | Jul 30, 2026 | The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap… | ||
| CVE-2026-66349 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing… | ||
| CVE-2026-65423 | Hig | 0.57 | 8.8 | 0.01 | Jul 30, 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write. | ||
| CVE-2026-65421 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition. | ||
| CVE-2026-63550 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position … | ||
| CVE-2026-63362 | Med | 0.38 | 5.9 | 0.02 | Jul 30, 2026 | An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet. | ||
| CVE-2026-63035 | Hig | 0.53 | 8.1 | 0.01 | Jul 30, 2026 | A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code. | ||
| CVE-2026-63033 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer. | ||
| CVE-2026-61893 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer. | ||
| CVE-2026-56758 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer. | ||
| CVE-2026-10031 | Med | 0.27 | 4.2 | 0.00 | Jul 30, 2026 | SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions… | ||
| CVE-2026-68563 | Med | 0.36 | 5.5 | 0.00 | Jul 30, 2026 | A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on… | ||
| CVE-2026-68562 | Med | 0.40 | 6.2 | 0.00 | Jul 30, 2026 | A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own… | ||
| CVE-2026-64816 | Med | 0.35 | 6.5 | 0.00 | Jul 30, 2026 | RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The… | ||
| CVE-2026-63559 | Hig | 0.49 | 7.5 | 0.00 | Jul 30, 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information. | ||
| CVE-2026-62845 | Med | 0.24 | 4.7 | 0.00 | Jul 30, 2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers.… | ||
| CVE-2026-62246 | Hig | 0.48 | 8.5 | 0.00 | Jul 30, 2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and… | ||
| CVE-2026-5846 | Med | 0.37 | 5.7 | 0.00 | Jul 30, 2026 | The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in… | ||
| CVE-2026-38709 | Cri | 0.64 | 9.8 | 0.03 | Jul 30, 2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to… | ||
| CVE-2026-18064 | Hig | 0.42 | 7.5 | 0.00 | Jul 30, 2026 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause… | ||
| CVE-2026-12562 | Hig | 0.57 | 8.8 | 0.00 | Jul 30, 2026 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service… | ||
| CVE-2026-68503 | Cri | 0.57 | 9.8 | 0.01 | Jul 30, 2026 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing… | ||
| CVE-2026-68502 | Cri | 0.57 | 9.8 | 0.01 | Jul 30, 2026 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and… | ||
| CVE-2026-68501 | Med | 0.35 | 6.5 | 0.00 | Jul 30, 2026 | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints… | ||
| CVE-2026-68500 | Hig | 0.42 | 7.5 | 0.00 | Jul 30, 2026 | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie… | ||
| CVE-2026-68499 | Med | 0.33 | 6.2 | 0.00 | Jul 30, 2026 | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop… | ||
| CVE-2026-66803 | Cri | 0.00 | 10.0 | 0.01 | Jul 30, 2026 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-66418 | Cri | 0.60 | 9.3 | 0.01 | Jul 30, 2026 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log.… | ||
| CVE-2026-61526 | Med | 0.33 | 6.1 | 0.00 | Jul 30, 2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route… | ||
| CVE-2026-55777 | Med | 0.27 | — | 0.00 | Jul 30, 2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove,… | ||
| CVE-2026-55768 | Hig | 0.50 | — | 0.00 | Jul 30, 2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before… | ||
| CVE-2026-54715 | Hig | 0.39 | — | 0.00 | Jul 30, 2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five,… | ||
| CVE-2026-52539 | Cri | 0.00 | 9.1 | 0.00 | Jul 30, 2026 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this… | ||
| CVE-2026-35847 | — | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file | |
| CVE-2025-69947 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. | ||
| CVE-2025-69941 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. | ||
| CVE-2025-69938 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. | ||
| CVE-2025-69937 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. | ||
| CVE-2025-69936 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. | ||
| CVE-2025-69935 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. | ||
| CVE-2025-69934 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. | ||
| CVE-2025-69933 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | ||
| CVE-2025-69931 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. | ||
| CVE-2025-69930 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | ||
| CVE-2025-65342 | Med | 0.00 | 6.1 | 0.00 | Jul 30, 2026 | code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. | ||
| CVE-2025-65341 | Med | 0.00 | 6.1 | 0.00 | Jul 30, 2026 | Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. | ||
| CVE-2025-65336 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. | ||
| CVE-2026-67594 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing… |
- risk 0.42cvss 6.5epss 0.00
The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly,…
- risk 0.42cvss 6.5epss 0.00
The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length,…
- risk 0.49cvss 7.5epss 0.00
The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap…
- risk 0.42cvss 6.5epss 0.00
The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing…
- risk 0.57cvss 8.8epss 0.01
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.
- risk 0.42cvss 6.5epss 0.00
The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.
- risk 0.42cvss 6.5epss 0.00
The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position …
- risk 0.38cvss 5.9epss 0.02
An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.
- risk 0.53cvss 8.1epss 0.01
A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.
- risk 0.42cvss 6.5epss 0.00
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.
- risk 0.42cvss 6.5epss 0.00
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.
- risk 0.42cvss 6.5epss 0.00
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.
- risk 0.27cvss 4.2epss 0.00
SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions…
- risk 0.36cvss 5.5epss 0.00
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on…
- risk 0.40cvss 6.2epss 0.00
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own…
- risk 0.35cvss 6.5epss 0.00
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The…
- risk 0.49cvss 7.5epss 0.00
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.
- risk 0.24cvss 4.7epss 0.00
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers.…
- risk 0.48cvss 8.5epss 0.00
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and…
- risk 0.37cvss 5.7epss 0.00
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in…
- risk 0.64cvss 9.8epss 0.03
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to…
- risk 0.42cvss 7.5epss 0.00
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause…
- risk 0.57cvss 8.8epss 0.00
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service…
- risk 0.57cvss 9.8epss 0.01
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing…
- risk 0.57cvss 9.8epss 0.01
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and…
- risk 0.35cvss 6.5epss 0.00
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints…
- risk 0.42cvss 7.5epss 0.00
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie…
- risk 0.33cvss 6.2epss 0.00
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop…
- risk 0.00cvss 10.0epss 0.01
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- risk 0.60cvss 9.3epss 0.01
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log.…
- risk 0.33cvss 6.1epss 0.00
AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route…
- risk 0.27cvss —epss 0.00
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove,…
- risk 0.50cvss —epss 0.00
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before…
- risk 0.39cvss —epss 0.00
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five,…
- risk 0.00cvss 9.1epss 0.00
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this…
- risk 0.00cvss 9.8epss 0.00
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
- risk 0.00cvss 9.8epss 0.00
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
- risk 0.00cvss 9.8epss 0.00
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
- risk 0.00cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
- risk 0.00cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
- risk 0.00cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
- risk 0.00cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
- risk 0.00cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
- risk 0.00cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
- risk 0.00cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
- risk 0.00cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
- risk 0.00cvss 6.1epss 0.00
code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.
- risk 0.00cvss 6.1epss 0.00
Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
- risk 0.00cvss 9.8epss 0.00
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
- risk 0.00cvss 9.8epss 0.00
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing…