|
5001
|
7.5 |
HIGH
Network
|
firebirdsql
|
firebird
|
Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passes an unprepared stru…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28212
|
2026-04-25 04:54 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5002
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-26160
|
2026-04-25 04:53 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5003
|
6.5 |
MEDIUM
Network
|
firebirdsql
|
firebird
|
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when …
|
CWE-190 CWE-835
Integer Overflow or Wraparound Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-28214
|
2026-04-25 04:47 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5004
|
8.2 |
HIGH
Network
|
firebirdsql
|
firebird
|
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, …
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28224
|
2026-04-25 04:45 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5005
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
|
CWE-20 CWE-822
Improper Input Validation Untrusted Pointer Dereference
|
CVE-2026-26161
|
2026-04-25 04:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5006
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.
|
CWE-843
Type Confusion
|
CVE-2026-26162
|
2026-04-25 04:31 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5007
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-26163
|
2026-04-25 04:30 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5008
|
7.2 |
HIGH
Network
|
dlink
|
dir-823x_firmware
|
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiti…
|
CWE-77
Command Injection
|
CVE-2025-29635
|
2026-04-25 04:27 |
2025-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5009
|
7.2 |
HIGH
Network
|
dlink
|
dir-823x_firmware
|
Una vulnerabilidad de inyección de comandos en D-Link DIR-823X 240126 y 240802 permite a un atacante autorizado ejecutar comandos arbitrarios en dispositivos remotos enviando una solicitud POST a /go…
|
CWE-77
Command Injection
|
CVE-2025-29635
|
2026-04-25 04:27 |
2025-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5010
|
7.2 |
HIGH
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to…
|
CWE-59 CWE-22
Link Following Path Traversal
|
CVE-2024-57728
|
2026-04-25 04:27 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5011
|
7.2 |
HIGH
Network
|
simple-help
|
simplehelp
|
El software de soporte remoto SimpleHelp v5.5.7 y versiones anteriores permite a los usuarios administradores cargar archivos arbitrarios en cualquier parte del sistema de archivos mediante la carga…
|
CWE-59 CWE-22
Link Following Path Traversal
|
CVE-2024-57728
|
2026-04-25 04:27 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5012
|
9.9 |
CRITICAL
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate p…
|
NVD-CWE-noinfo CWE-862
Missing Authorization
|
CVE-2024-57726
|
2026-04-25 04:26 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5013
|
9.9 |
CRITICAL
Network
|
simple-help
|
simplehelp
|
El software de soporte remoto SimpleHelp v5.5.7 y versiones anteriores tiene una vulnerabilidad que permite a los técnicos con pocos privilegios crear claves API con permisos excesivos. Estas claves…
|
NVD-CWE-noinfo CWE-862
Missing Authorization
|
CVE-2024-57726
|
2026-04-25 04:26 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5014
|
7.5 |
HIGH
Network
|
xiangshan
|
nemu
|
NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decoder does not correctly validate the funct3 field when decodin…
|
CWE-131 CWE-1287
Incorrect Calculation of Buffer Size Improper Validation of Specified Type of Input
|
CVE-2026-29645
|
2026-04-25 04:25 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5015
|
9.8 |
CRITICAL
Network
|
xiangshan
|
nemu
|
NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/updated based on menvcfg[7:4], so a machine-mode w…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-29649
|
2026-04-25 04:23 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5016
|
3.3 |
LOW
Local
|
uutils
|
coreutils
|
A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) options together. The im…
|
CWE-684
Incorrect Provision of Specified Functionality
|
CVE-2026-35381
|
2026-04-25 04:19 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5017
|
6.5 |
MEDIUM
Network
|
roxy-wi
|
roxy-wi
|
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is dir…
|
CWE-24
Path Traversal: '../filedir'
|
CVE-2026-33431
|
2026-04-25 04:19 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5018
|
6.3 |
MEDIUM
Local
|
uutils
|
coreutils
|
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils during cross-device operations. The utility removes the destination path before recreating it throu…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35364
|
2026-04-25 04:19 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5019
|
3.3 |
LOW
Local
|
uutils
|
coreutils
|
The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted permissions. This causes the file to inherit umask-based permissions, typicall…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-35367
|
2026-04-25 04:19 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5020
|
7.8 |
HIGH
Local
|
uutils
|
coreutils
|
A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before drop…
|
CWE-426
Untrusted Search Path
|
CVE-2026-35368
|
2026-04-25 04:18 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5021
|
9.1 |
CRITICAL
Network
|
roxy-wi
|
roxy-wi
|
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search …
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2026-33432
|
2026-04-25 04:18 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5022
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
x86/fred: Correct speculative safety in fred_extint()
array_index_nospec() is no use if the result gets spilled to the stack, as
…
|
CWE-129
Improper Validation of Array Index
|
CVE-2026-23354
|
2026-04-25 04:15 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5023
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
x86/fred: Corregir la seguridad especulativa en fred_extint()
array_index_nospec() no sirve de nada si el resultado se vuelca a …
|
CWE-129
Improper Validation of Array Index
|
CVE-2026-23354
|
2026-04-25 04:15 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5024
|
4.3 |
MEDIUM
Network
|
wolfssh
|
wolfssh
|
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which w…
|
CWE-126 CWE-125
Buffer Over-read Out-of-bounds Read
|
CVE-2026-0930
|
2026-04-25 04:15 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5025
|
7.6 |
HIGH
Network
|
hkuds
|
openharness
|
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exp…
|
CWE-287
Improper Authentication
|
CVE-2026-6729
|
2026-04-25 04:14 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5026
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ata: libata: cancel pending work after clearing deferred_qc
Syzbot reported a WARN_ON() in ata_scsi_deferred_qc_work(), caused by…
|
NVD-CWE-noinfo
|
CVE-2026-23355
|
2026-04-25 04:13 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5027
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
ata: libata: cancelar trabajo pendiente después de limpiar deferred_qc
Syzbot informó un WARN_ON() en ata_scsi_deferred_qc_work(…
|
NVD-CWE-noinfo
|
CVE-2026-23355
|
2026-04-25 04:13 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5028
|
6.5 |
MEDIUM
Network
|
nicolargo
|
glances
|
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cr…
|
CWE-200 CWE-306 CWE-942
Information Exposure Missing Authentication for Critical Function Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-34839
|
2026-04-25 04:09 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5029
|
3.3 |
LOW
Local
|
uutils
|
coreutils
|
A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when utilizing the -S (split-string) option. In GNU env, backslashes within single quot…
|
CWE-20
Improper Input Validation
|
CVE-2026-35377
|
2026-04-25 04:06 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5030
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
Even though we check that we "should" be able to do lc_get_cumulative()
whil…
|
CWE-617
Reachable Assertion
|
CVE-2026-23356
|
2026-04-25 04:06 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5031
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
drbd: corrige el 'LOGIC BUG' en drbd_al_begin_io_nonblock()
Aunque verificamos que "deberíamos" poder hacer lc_get_cumulative() …
|
CWE-617
Reachable Assertion
|
CVE-2026-23356
|
2026-04-25 04:06 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5032
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
can: mcp251x: fix deadlock in error path of mcp251x_open
The mcp251x_open() function call free_irq() in its error path with the
m…
|
CWE-667
Improper Locking
|
CVE-2026-23357
|
2026-04-25 04:04 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5033
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
can: mcp251x: corregir interbloqueo en la ruta de error de mcp251x_open
La función mcp251x_open() llama a free_irq() en su ruta …
|
CWE-667
Improper Locking
|
CVE-2026-23357
|
2026-04-25 04:04 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5034
|
4.7 |
MEDIUM
Local
|
uutils
|
coreutils
|
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device moves. The extended attribute (xattr) preservation logic uses multiple path-base…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35354
|
2026-04-25 04:04 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5035
|
6.6 |
MEDIUM
Local
|
uutils
|
coreutils
|
The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bit…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2026-35350
|
2026-04-25 04:04 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5036
|
5.7 |
MEDIUM
Adjacent
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections. Attackers can forge discovery results or craft s…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-40045
|
2026-04-25 04:03 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5037
|
7.0 |
HIGH
Local
|
uutils
|
coreutils
|
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local at…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35352
|
2026-04-25 04:03 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5038
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix error handling in slot reset
If the device has not recovered after slot reset is called, it goes to
out label for…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-23358
|
2026-04-25 04:03 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5039
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
drm/amdgpu: Corregir el manejo de errores en el reinicio de ranura
Si el dispositivo no se ha recuperado después de que se llama…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-23358
|
2026-04-25 04:03 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5040
|
4.7 |
MEDIUM
Local
|
uutils
|
coreutils
|
The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are initially created with umask-derived permissions (e.g., 0644) before being restrict…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35357
|
2026-04-25 04:02 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5041
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix stack-out-of-bounds write in devmap
get_upper_ifindexes() iterates over all upper devices and writes their
indices into …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-23359
|
2026-04-25 04:02 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5042
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
bpf: Corrección de escritura fuera de límites de la pila en devmap
get_upper_ifindexes() itera sobre todos los dispositivos supe…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-23359
|
2026-04-25 04:02 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5043
|
4.7 |
MEDIUM
Local
|
uutils
|
coreutils
|
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass no-dereference intent. The utility checks if a source path is a symbolic link …
|
CWE-59 CWE-367
Link Following Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35359
|
2026-04-25 04:02 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5044
|
6.3 |
MEDIUM
Local
|
uutils
|
coreutils
|
The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creat…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35360
|
2026-04-25 04:02 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5045
|
5.6 |
MEDIUM
Local
|
uutils
|
coreutils
|
A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the utility correctly refuses to delete . or .., it fa…
|
CWE-22
Path Traversal
|
CVE-2026-35363
|
2026-04-25 04:02 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5046
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nvme: fix admin queue leak on controller reset
When nvme_alloc_admin_tag_set() is called during a controller reset,
a previous ad…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-23360
|
2026-04-25 03:59 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5047
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
nvme: corrige la fuga de la cola de administración al reiniciar el controlador
Cuando se llama a nvme_alloc_admin_tag_set() dura…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-23360
|
2026-04-25 03:59 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5048
|
4.3 |
MEDIUM
Adjacent
|
openbsd
|
openbsd
|
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_o…
|
CWE-1284 CWE-835
Improper Validation of Specified Quantity in Input Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-41285
|
2026-04-25 03:59 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5049
|
5.5 |
MEDIUM
Local
|
uutils
|
coreutils
|
The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and ut…
|
CWE-248
Uncaught Exception
|
CVE-2026-35348
|
2026-04-25 03:57 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5050
|
7.5 |
HIGH
|
softbizscripts
|
dating_script
|
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parame…
|
NVD-CWE-Other
|
CVE-2006-3271
|
2026-04-25 03:56 |
2006-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|