|
1151
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magic-conversation' shortcode in all versions up to, and including, 3.0.97 due to i…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1396
|
2026-04-25 03:15 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1152
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
arm64: io: Extract user memory type in ioremap_prot()
The only caller of ioremap_prot() outside of the generic ioremap()
implemen…
|
NVD-CWE-noinfo
|
CVE-2026-23346
|
2026-04-25 03:15 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1153
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
arm64: io: Extraer el tipo de memoria de usuario en ioremap_prot()
El único llamador de ioremap_prot() fuera de la implementació…
|
NVD-CWE-noinfo
|
CVE-2026-23346
|
2026-04-25 03:15 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1154
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the co…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5532
|
2026-04-25 03:14 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1155
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Han…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5533
|
2026-04-25 03:14 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1156
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Online Enrollment System 1.0. This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the component Parameter Handler. Such …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5534
|
2026-04-25 03:14 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1157
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5537
|
2026-04-25 03:14 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1158
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_url of the component judge_server_heartbeat Endpoi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5538
|
2026-04-25 03:14 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1159
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember.php of the component Parameter Handler. This manipulation of the argument firs…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5539
|
2026-04-25 03:14 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1160
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modifymember.php of the component Parameter Handler. Such manipulation …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5540
|
2026-04-25 03:14 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|