|
801
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The manipulation leads to improper authorizati…
Update
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-6977
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
802
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sq…
Update
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6978
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
803
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes serve…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6979
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
804
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url …
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6983
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
805
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The mani…
Update
|
CWE-791 CWE-1336
Incomplete Filtering of Special Elements Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-6984
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
806
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation result…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6987
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
807
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument Nome/Descriçã…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6990
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
808
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Exec…
Update
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6991
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
809
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipula…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6995
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
810
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can le…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6996
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|