|
2151
|
9.8 |
CRITICAL
Network
|
dnnsoftware
|
dotnetnuke
|
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2794
|
2026-04-25 02:34 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2152
|
9.8 |
CRITICAL
Network
|
dnnsoftware
|
dotnetnuke
|
El asistente de instalación en DotNetNuke (DNN) en versiones anteriores a 7.4.1 permite a atacantes remotos reinstalar la aplicación y obtener acceso SuperUser a través de una solicitud directa a Ins…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2794
|
2026-04-25 02:34 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2153
|
6.1 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
|
CWE-126
Buffer Over-read
|
CVE-2026-26169
|
2026-04-25 02:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2154
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
|
CWE-20
Improper Input Validation
|
CVE-2026-26170
|
2026-04-25 02:22 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2155
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26172
|
2026-04-25 02:21 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2156
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locall…
|
CWE-362 CWE-416 CWE-476
Race Condition Use After Free NULL Pointer Dereference
|
CVE-2026-26173
|
2026-04-25 02:20 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2157
|
6.1 |
MEDIUM
Network
|
-
|
-
|
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when s…
|
CWE-79
Cross-site Scripting
|
CVE-2026-41305
|
2026-04-25 02:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2158
|
8.0 |
HIGH
Network
|
-
|
-
|
Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all the users in the application, resulting in executing the code…
|
CWE-79
Cross-site Scripting
|
CVE-2026-31281
|
2026-04-25 02:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2159
|
6.5 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryTreeProof::verify` panics on a malformed proof where `history.len() != …
|
CWE-617
Reachable Assertion
|
CVE-2026-34067
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2160
|
5.3 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStore::put_historic_txns` uses an `assert!` to enforce invariants about `HistoricTr…
|
CWE-20 CWE-617 CWE-754
Improper Input Validation Reachable Assertion Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-34066
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2161
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announci…
|
CWE-252 CWE-755
Unchecked Return Value Improper Handling of Exceptional Conditions
|
CVE-2026-34065
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2162
|
8.2 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::InsufficientFunds` when `new_…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-34064
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2163
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there…
|
CWE-617
Reachable Assertion
|
CVE-2026-34063
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2164
|
5.3 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer c…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-34062
|
2026-04-25 02:11 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2165
|
9.6 |
CRITICAL
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each…
|
CWE-20 CWE-190 CWE-345 CWE-1284
Improper Input Validation Integer Overflow or Wraparound Insufficient Verification of Data Authenticity Improper Validation of Specified Quantity in Input
|
CVE-2026-33471
|
2026-04-25 02:11 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2166
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an untrusted peer could crash a validator by …
|
CWE-125 CWE-193
Out-of-bounds Read Off-by-one Error
|
CVE-2026-32605
|
2026-04-25 02:11 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2167
|
8.1 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for non-skip blocks an…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-40093
|
2026-04-25 02:11 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2168
|
5.3 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 and below, an unauthenticated p2p peer can cause th…
|
CWE-617
Reachable Assertion
|
CVE-2026-34069
|
2026-04-25 02:10 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2169
|
6.8 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions that set `new_votin…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-34068
|
2026-04-25 02:10 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2170
|
8.1 |
HIGH
Network
|
sgbett
|
bsv-wallet bsv_ruby_sdk
|
BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier'…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-40070
|
2026-04-25 02:03 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2171
|
9.0 |
CRITICAL
Network
|
thymeleaf
|
thymeleaf
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. A…
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40477
|
2026-04-25 01:58 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2172
|
9.0 |
CRITICAL
Network
|
thymeleaf
|
thymeleaf
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanism…
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40478
|
2026-04-25 01:58 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2173
|
7.5 |
HIGH
Network
|
monetr
|
monetr
|
monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe sig…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40481
|
2026-04-25 01:57 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2174
|
5.3 |
MEDIUM
Network
|
fastapiexpert
|
python-multipart
|
Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or…
|
CWE-400 CWE-834
Uncontrolled Resource Consumption Excessive Iteration
|
CVE-2026-40347
|
2026-04-25 01:51 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2175
|
8.8 |
HIGH
Network
|
nextcloud windmill
|
flow windmill
|
Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the …
|
CWE-862
Missing Authorization
|
CVE-2026-22683
|
2026-04-25 01:49 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2176
|
7.5 |
HIGH
Network
|
powerdns
|
dnsdist
|
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released unt…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-33594
|
2026-04-25 01:48 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2177
|
8.8 |
HIGH
Local
|
nsa
|
emissary
|
Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /b…
|
CWE-78 CWE-116
OS Command Improper Encoding or Escaping of Output
|
CVE-2026-35582
|
2026-04-25 01:48 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2178
|
8.3 |
HIGH
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST…
|
CWE-352
Origin Validation Error
|
CVE-2026-40925
|
2026-04-25 01:46 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2179
|
5.7 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_cs_student_records
|
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerab…
|
CWE-284
Improper Access Control
|
CVE-2026-35241
|
2026-04-25 01:44 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2180
|
7.8 |
HIGH
Local
|
oracle
|
application_development_framework
|
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. E…
|
CWE-284
Improper Access Control
|
CVE-2026-35243
|
2026-04-25 01:43 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2181
|
9.1 |
CRITICAL
Network
|
oracle
|
enterprise_manager_base_platform
|
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily explo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-34279
|
2026-04-25 01:43 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2182
|
6.0 |
MEDIUM
Local
|
oracle
|
graalvm jdk jre
|
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u481 and 8u481-b50; …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-22003
|
2026-04-25 01:42 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2183
|
4.4 |
MEDIUM
Local
|
libjxl_project
|
libjxl
|
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory.
This can be done by causing the decoder to reference an outside-image-bound area in …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2025-12474
|
2026-04-25 01:42 |
2026-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2184
|
4.4 |
MEDIUM
Local
|
libjxl_project
|
libjxl
|
Un archivo especialmente diseñado puede provocar que el decodificador de libjxl lea datos de píxeles de memoria no inicializada (pero asignada).
Esto se puede lograr al provocar que el decodificador…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2025-12474
|
2026-04-25 01:42 |
2026-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2185
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…
|
CWE-416
Use After Free
|
CVE-2026-6919
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2186
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6920
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2187
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
|
CWE-362
Race Condition
|
CVE-2026-6921
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2188
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javas…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-41269
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2189
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix missing bounds check on DEFAULT table in verify_dfa()
The verify_dfa() function only checks DEFAULT_TABLE bounds wh…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-23407
|
2026-04-25 01:38 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2190
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
i2c: i801: Revert "i2c: i801: replace acpi_lock with I2C bus lock"
This reverts commit f707d6b9e7c18f669adfdb443906d46cfbaaa0c1.
…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23369
|
2026-04-25 01:38 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2191
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data
set_new_password() hex dumps the entire buffer, which conta…
|
NVD-CWE-noinfo
|
CVE-2026-23370
|
2026-04-25 01:37 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2192
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
platform/x86: dell-wmi-sysman: No volcar en hexadecimal datos de contraseña en texto plano
set_new_password() vuelca en hexadeci…
|
NVD-CWE-noinfo
|
CVE-2026-23370
|
2026-04-25 01:37 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2193
|
8.3 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain co…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41271
|
2026-04-25 01:37 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2194
|
7.1 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Sid…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41272
|
2026-04-25 01:37 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2195
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /admin/mod_room/index.php?view=edit. Executing a manipulation of the argument ID c…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4966
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2196
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-4968
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2197
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the a…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4969
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2198
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4970
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2199
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack is possible to be carried…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-4971
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2200
|
2.4 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.ph…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4972
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|