|
901
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file …
New
|
CWE-200 CWE-538
Information Exposure File and Directory Information Exposure
|
CVE-2026-7071
|
2026-04-27 10:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
902
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in code-projects Inventory Management System 1.0. Affected is an unknown function of the component Login. Executing a manipulation of the argument Username can lead to …
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7070
|
2026-04-27 10:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
903
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argum…
New
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7069
|
2026-04-27 09:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
904
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack ca…
New
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7068
|
2026-04-27 09:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
905
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argumen…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7067
|
2026-04-27 09:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
906
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function exec_openstack of the file server.py. The manipulati…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7066
|
2026-04-27 09:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
907
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the comp…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7065
|
2026-04-27 09:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
908
|
9.3 |
CRITICAL
Network
|
-
|
-
|
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An att…
New
|
CWE-656
Reliance on Security Through Obscurity
|
CVE-2026-42363
|
2026-04-27 09:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
909
|
7.5 |
HIGH
Network
|
libexpat_project
|
libexpat
|
libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Update
|
CWE-331
Insufficient Entropy
|
CVE-2026-41080
|
2026-04-27 07:17 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
910
|
7.1 |
HIGH
Network
|
elog_project
|
elog
|
ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attac…
Update
|
CWE-862
Missing Authorization
|
CVE-2025-64348
|
2026-04-27 04:26 |
2025-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
911
|
7.1 |
HIGH
Network
|
elog_project
|
elog
|
ELOG permite a un usuario autenticado modificar o sobrescribir el archivo de configuración, resultando en denegación de servicio. Si la función de ejecución está específicamente habilitada con el ind…
Update
|
CWE-862
Missing Authorization
|
CVE-2025-64348
|
2026-04-27 04:26 |
2025-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
9.8 |
CRITICAL
Network
|
newforma
|
project_center
|
Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AU…
Update
|
CWE-306 CWE-502
Missing Authentication for Critical Function Deserialization of Untrusted Data
|
CVE-2025-35051
|
2026-04-27 04:04 |
2025-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
- |
-
|
-
|
-
|
The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not p…
Update
|
CWE-1393
Use of Default Password
|
CVE-2025-26793
|
2026-04-27 03:56 |
2025-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
- |
-
|
-
|
-
|
El panel de configuración de la interfaz gráfica de usuario web de Hirsch (anteriormente Identiv y Viscount) Enterphone MESH hasta 2024 se entrega con credenciales predeterminadas (nombre de usuario …
Update
|
CWE-1393
Use of Default Password
|
CVE-2025-26793
|
2026-04-27 03:56 |
2025-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
- |
-
|
-
|
-
|
Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
Update
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2025-1790
|
2026-04-27 03:49 |
2026-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
- |
-
|
-
|
-
|
Escalada de privilegios local en el plugin Genetec Sipelia. Un usuario de Windows autenticado con bajos privilegios podría explotar esta vulnerabilidad para obtener privilegios elevados en el sistema…
Update
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2025-1790
|
2026-04-27 03:49 |
2026-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
7.8 |
HIGH
Local
|
genetec
|
genetec_update_service
|
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
Update
|
CWE-276
Incorrect Default Permissions
|
CVE-2025-1789
|
2026-04-27 03:49 |
2026-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
7.8 |
HIGH
Local
|
genetec
|
genetec_update_service
|
Escalada de privilegios local en el Servicio de Actualización de Genetec. Un usuario de Windows autenticado y con pocos privilegios podría explotar esta vulnerabilidad para obtener privilegios elevad…
Update
|
CWE-276
Incorrect Default Permissions
|
CVE-2025-1789
|
2026-04-27 03:49 |
2026-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
4.2 |
MEDIUM
Local
|
genetec
|
genetec_update_service
|
Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privil…
Update
|
CWE-346
Origin Validation Error
|
CVE-2025-1787
|
2026-04-27 03:49 |
2026-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
4.2 |
MEDIUM
Local
|
genetec
|
genetec_update_service
|
El administrador local podría filtrar información de la página web de configuración del Servicio de Actualización de Genetec. Un usuario de Windows autenticado y con privilegios de administrador podr…
Update
|
CWE-346
Origin Validation Error
|
CVE-2025-1787
|
2026-04-27 03:49 |
2026-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
921
|
8.8 |
HIGH
Network
|
mrsilaz
|
mfa_mail
|
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-4208
|
2026-04-26 03:43 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
922
|
8.8 |
HIGH
Network
|
mrsilaz
|
mfa_mail
|
La extensión no restablece correctamente el código MFA generado después de una autenticación exitosa. Esto conduce a una posible omisión de MFA para futuros intentos de inicio de sesión al proporcion…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-4208
|
2026-04-26 03:43 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
923
|
4.3 |
MEDIUM
Network
|
ayacoo
|
redirect_tab
|
The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of redirect records when editing a page.
Update
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-4202
|
2026-04-26 03:40 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
924
|
4.3 |
MEDIUM
Network
|
ayacoo
|
redirect_tab
|
La extensión falla al verificar si un usuario autenticado tiene permisos para acceder a las redirecciones, resultando en la exposición de registros de redirección al editar una página.
Update
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-4202
|
2026-04-26 03:40 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
925
|
8.8 |
HIGH
Network
|
cps-it
|
mailqueue
|
The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active explo…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-1323
|
2026-04-26 03:37 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
926
|
8.8 |
HIGH
Network
|
cps-it
|
mailqueue
|
La extensión no define correctamente las clases permitidas utilizadas al deserializar metadatos de fallo de transporte. Un atacante puede explotar esto para ejecutar código serializado no confiable. …
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-1323
|
2026-04-26 03:37 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
927
|
9.4 |
CRITICAL
Network
|
dgraph
|
dgraph
|
Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered o…
Update
|
CWE-200 CWE-215 CWE-522
Information Exposure Insertion of Sensitive Information Into Debugging Code Insufficiently Protected Credentials
|
CVE-2026-40173
|
2026-04-26 03:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
928
|
7.8 |
HIGH
Local
|
getcomposer
|
composer
|
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs she…
Update
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2026-40176
|
2026-04-26 03:24 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
929
|
6.1 |
MEDIUM
Network
|
apostrophecms
|
apostrophecms sanitize-html
|
ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasse…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-40186
|
2026-04-26 03:15 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
930
|
8.8 |
HIGH
Network
|
getcomposer
|
composer
|
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $source…
Update
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2026-40261
|
2026-04-26 03:12 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
931
|
8.1 |
HIGH
Network
|
hashicorp
|
vault
|
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulne…
Update
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-3605
|
2026-04-26 03:08 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
932
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
Update
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2025-52660
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
933
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de carga de archivos sin restricciones. Esto puede permitir cargas de archivos maliciosos, lo que podría resultar en ejecución de código no autorizada o …
Update
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2025-52660
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
934
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibili…
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-55249
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
935
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de encabezados de respuesta de seguridad faltantes. La ausencia de encabezados de seguridad estándar puede debilitar la postura de seguridad general de l…
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-55249
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
936
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-55251
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
937
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de carga de archivos sin restricciones. Esto puede permitir cargas de archivos maliciosos, lo que podría resultar en ejecución de código no autorizada o …
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-55251
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
938
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access
Update
|
CWE-521
Weak Password Requirements
|
CVE-2025-55252
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
939
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectado por una vulnerabilidad de política de contraseñas débil. Esto puede permitir el uso de contraseñas fácilmente adivinables, lo que podría resultar en acceso no autoriz…
Update
|
CWE-521
Weak Password Requirements
|
CVE-2025-55252
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
940
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.
Update
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2025-55250
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
941
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectado por una vulnerabilidad de revelación de errores técnicos. Esto puede exponer detalles técnicos sensibles, lo que podría resultar en revelación de información o facili…
Update
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2025-55250
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
Update
|
CWE-613
Insufficient Session Expiration
|
CVE-2025-52661
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectada por una vulnerabilidad de JWT Token Expiry Too Long. Esto puede aumentar el riesgo de uso indebido del token, lo que podría resultar en acceso no autorizado si el tok…
Update
|
CWE-613
Insufficient Session Expiration
|
CVE-2025-52661
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or informa…
Update
|
CWE-525
Use of Web Browser Cache Containing Sensitive Information
|
CVE-2025-52659
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectada por una vulnerabilidad de respuesta HTTP cacheable. Esto puede llevar al almacenamiento no intencionado de contenido sensible o dinámico, lo que podría resultar en ac…
Update
|
CWE-525
Use of Web Browser Cache Containing Sensitive Information
|
CVE-2025-52659
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially le…
Update
|
CWE-200
Information Exposure
|
CVE-2025-52649
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION se ve afectado por una vulnerabilidad donde ciertos identificadores pueden ser predecibles por naturaleza. Los identificadores predecibles pueden permitir a un atacante inferir o adivinar va…
Update
|
CWE-200
Information Exposure
|
CVE-2025-52649
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modifie…
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-52645
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad donde los mecanismos de empaquetado y distribución de modelos podrían no incluir suficiente verificación de autenticidad. Esto podría permitir la posibil…
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-52645
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
7.8 |
HIGH
Local
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security …
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-52643
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|