|
1101
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The manipulation leads to improper authorizati…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-6977
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1102
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sq…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6978
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1103
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes serve…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6979
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1104
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6983
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1105
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The mani…
|
CWE-791 CWE-1336
Incomplete Filtering of Special Elements Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-6984
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1106
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument Nome/Descriçã…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6990
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1107
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Exec…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6991
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1108
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipula…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6995
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1109
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can le…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6996
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1110
|
2.4 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner l…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6997
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|