|
461
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipul…
Update
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-6571
|
2026-04-23 05:22 |
2026-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
462
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app/controller/share.class.php of the component fileU…
Update
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-6572
|
2026-04-23 05:22 |
2026-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
463
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of t…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6573
|
2026-04-23 05:22 |
2026-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
464
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation…
Update
|
CWE-259 CWE-798
Use of Hard-coded Password Use of Hard-coded Credentials
|
CVE-2026-6574
|
2026-04-23 05:22 |
2026-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
465
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat Bot Int…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6576
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
466
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulati…
Update
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-6577
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
467
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing a…
Update
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-6579
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
468
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler. Such manipu…
Update
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-6580
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
469
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of…
Update
|
CWE-259 CWE-798
Use of Hard-coded Password Use of Hard-coded Credentials
|
CVE-2026-6578
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
470
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a manipulation of the argument p…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-6581
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|