|
2051
|
7.1 |
HIGH
Network
|
-
|
-
|
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action han…
|
CWE-73
External Control of File Name or Path
|
CVE-2026-5809
|
2026-04-25 03:00 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2052
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddleware of the file apps/common/middleware/static_headers_middleware.py of the co…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6106
|
2026-04-25 03:00 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2053
|
3.5 |
LOW
Network
|
-
|
-
|
A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/common/middleware/chat_headers_middleware.py of the component ChatHeadersMiddleware.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6107
|
2026-04-25 03:00 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2054
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_mcp_node.py of the component Mod…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-6108
|
2026-04-25 03:00 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2055
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
x86/efi: defer freeing of boot services memory
efi_free_boot_services() frees memory occupied by EFI_BOOT_SERVICES_CODE
and EFI_B…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-23352
|
2026-04-25 02:59 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2056
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
x86/efi: aplazar la liberación de la memoria de servicios de arranque
efi_free_boot_services() libera la memoria ocupada por EFI…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-23352
|
2026-04-25 02:59 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2057
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload End…
|
CWE-264 CWE-265
Permissions, Privileges, and Access Controls Privilege Issues
|
CVE-2026-6117
|
2026-04-25 02:58 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2058
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. This manipulat…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6118
|
2026-04-25 02:58 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2059
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation leads to server-side request fo…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6119
|
2026-04-25 02:58 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2060
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler…
|
CWE-74 CWE-94
Injection Code Injection
|
CVE-2026-6125
|
2026-04-25 02:58 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2061
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missin…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-6126
|
2026-04-25 02:58 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2062
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing aut…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-6129
|
2026-04-25 02:58 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2063
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server …
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-6130
|
2026-04-25 02:58 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2064
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/Tools/parse_url.ts. Executing a manipulation can lea…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-6141
|
2026-04-25 02:58 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2065
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. Affected by this vulnerability is an unknown functionality of the file /admin/roo…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6142
|
2026-04-25 02:58 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2066
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. …
|
CWE-346 CWE-942
Origin Validation Error Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-6143
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2067
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in code-projects Vehicle Showroom Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /util/MonthTotalReportUpdateFunction.php. …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6148
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2068
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Affected by this issue is some unknown functionality of the file /util/BookVehicleFunction.php. Executing a manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6149
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2069
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /checkupdatestatus.php. The manipulation of the argument serviceId leads to cross s…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6150
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2070
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/PaymentStatusFunction.php. The manipulation of the argumen…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6151
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2071
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/StaffAddingFunction.php. This manipulation of the …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6152
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2072
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /util/StaffDetailsFunction.php. Such manipulation of the argument S…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6153
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2073
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown functionality of the file /chatbox/insert.php of the component Endpoint. Such ma…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6159
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2074
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation re…
|
CWE-200 CWE-538
Information Exposure File and Directory Information Exposure
|
CVE-2026-6160
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2075
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the component Endpoint. Executing a manipulation of the argum…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6161
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2076
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdat…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6162
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2077
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file /catageory.php. Such manipulation of the argument…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6163
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2078
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Performing a manipulation of the argument cata results …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6164
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2079
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/Login_check.php. Executing a manipulation of the argu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6165
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2080
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/UpdateVehicleFunction.php. The manipul…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6166
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2081
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file /subject-print.php. The manipulation of the argument ID results in sql injecti…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6167
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2082
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview. Such manipulation leads to cross site scripting.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-15632
|
2026-04-25 02:57 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2083
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, m…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-6911
|
2026-04-25 02:56 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2084
|
8.8 |
HIGH
Network
|
-
|
-
|
Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to …
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-6912
|
2026-04-25 02:56 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2085
|
4.9 |
MEDIUM
Network
|
-
|
-
|
Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code
|
CWE-79
Cross-site Scripting
|
CVE-2026-31050
|
2026-04-25 02:55 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2086
|
3.8 |
LOW
Network
|
-
|
-
|
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-31051
|
2026-04-25 02:55 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2087
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout Authentication Flow component
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-31052
|
2026-04-25 02:55 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2088
|
4.0 |
MEDIUM
Local
|
-
|
-
|
bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-42095
|
2026-04-25 02:55 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2089
|
9.8 |
CRITICAL
Network
|
-
|
-
|
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated …
|
CWE-1188 CWE-1391
Insecure Default Initialization of Resource Use of Weak Credentials
|
CVE-2026-39920
|
2026-04-25 02:55 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2090
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch…
|
CWE-79
Cross-site Scripting
|
CVE-2025-61872
|
2026-04-25 02:54 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2091
|
4.7 |
MEDIUM
Network
|
-
|
-
|
In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution f…
|
CWE-284
Improper Access Control
|
CVE-2025-59308
|
2026-04-25 02:54 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2092
|
5.4 |
MEDIUM
Network
|
opensourcepos
|
open_source_point_of_sale
|
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Lo…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39380
|
2026-04-25 02:51 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2093
|
10.0 |
CRITICAL
Network
|
flatpak
|
flatpak
|
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at …
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-34078
|
2026-04-25 02:50 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2094
|
4.3 |
MEDIUM
Network
|
pretix
|
pretix
|
A new API endpoint introduced in pretix 2025 that is supposed to
return all check-in events of a specific event in fact returns all
check-in events belonging to the respective organizer. This allow…
|
CWE-653
Improper Isolation or Compartmentalization
|
CVE-2026-5600
|
2026-04-25 02:46 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2095
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ice: fix crash in ethtool offline loopback test
Since the conversion of ice to page pool, the ethtool loopback test
crashes:
BU…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23353
|
2026-04-25 02:45 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2096
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
ice: corrige un fallo en la prueba de bucle invertido fuera de línea de ethtool
Desde la conversión de ice a 'page pool', la pru…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23353
|
2026-04-25 02:45 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2097
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-26165
|
2026-04-25 02:39 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2098
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-26166
|
2026-04-25 02:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2099
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26167
|
2026-04-25 02:37 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2100
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locall…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26168
|
2026-04-25 02:35 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|