|
931
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command inject…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5528
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
932
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipul…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-5529
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
933
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5530
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
934
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. Th…
|
CWE-312 CWE-313
Cleartext Storage of Sensitive Information Cleartext Storage in a File or on Disk
|
CVE-2026-5531
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
935
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5198
|
2026-04-25 03:12 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
936
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserG…
|
CWE-22
Path Traversal
|
CVE-2026-5203
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
937
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such man…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5205
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
938
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argumen…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5206
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
939
|
2.4 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is some unknown functionality of the component User Management Handler. Such manipula…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5209
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
940
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a manipulation of the argument page results in file inclusion. Remote exploitatio…
|
CWE-73
External Control of File Name or Path
|
CVE-2026-5210
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|