|
881
|
- |
|
-
|
-
|
This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vu…
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-42518
|
2026-04-29 18:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
882
|
- |
|
-
|
-
|
This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulat…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-42517
|
2026-04-29 18:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
883
|
- |
|
-
|
-
|
This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vulnerability by manipulating encoded parameters in th…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-42516
|
2026-04-29 18:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
884
|
- |
|
-
|
-
|
This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API re…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-42515
|
2026-04-29 18:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
885
|
- |
|
-
|
-
|
This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTP…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-42514
|
2026-04-29 18:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
886
|
- |
|
-
|
-
|
This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vul…
|
-
|
CVE-2026-42513
|
2026-04-29 18:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
887
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WP User Frontend: from n/a through 4.3.1.
|
CWE-862
Missing Authorization
|
CVE-2026-42412
|
2026-04-29 18:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
888
|
7.3 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects SureForms Pro: from n/a through 2.8.…
|
CWE-862
Missing Authorization
|
CVE-2026-42377
|
2026-04-29 17:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
889
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-40556
|
2026-04-29 17:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
890
|
- |
|
-
|
-
|
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
|
-
|
CVE-2025-54505
|
2026-04-29 13:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|