|
711
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performin…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-7393
|
2026-04-30 02:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
712
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of …
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7392
|
2026-04-30 02:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
713
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action=save_supplier. This manipulation of the argument …
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7391
|
2026-04-30 02:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
714
|
6.1 |
MEDIUM
Local
|
artifex
|
mupdf
|
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulatio…
Update
|
CWE-119 CWE-125
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Read
|
CVE-2026-7233
|
2026-04-30 02:15 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
715
|
5.3 |
MEDIUM
Local
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit appro…
Update
|
CWE-184
Incomplete Blacklist
|
CVE-2026-41332
|
2026-04-30 02:10 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
716
|
4.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin authenticated clients. Non-admin clients can recover host-specific filesystem paths…
Update
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-41339
|
2026-04-30 02:06 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
717
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate EaNameLength in smb2_get_ea()
smb2_get_ea() reads ea_req->EaNameLength from the client request and
passes it dire…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31612
|
2026-04-30 02:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
718
|
8.6 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: require 3 sub-authorities before reading sub_auth[2]
parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on
m…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31611
|
2026-04-30 01:56 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
719
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc
The kernel ASN.1 BER decoder calls action callbacks incremen…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31610
|
2026-04-30 01:51 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
720
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush()
smbd_send_batch_flush() already calls smbd_fr…
Update
|
CWE-415
Double Free
|
CVE-2026-31609
|
2026-04-30 01:45 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|