|
761
|
- |
|
-
|
-
|
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted syste…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2025-14575
|
2026-05-19 23:46 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
762
|
- |
|
-
|
-
|
Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within da…
|
CWE-863
Incorrect Authorization
|
CVE-2026-42096
|
2026-05-19 23:45 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
763
|
- |
|
-
|
-
|
Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL qu…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-42097
|
2026-05-19 23:45 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
764
|
- |
|
-
|
-
|
Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e…
|
CWE-603
Use of Client-Side Authentication
|
CVE-2026-42098
|
2026-05-19 23:45 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
765
|
- |
|
-
|
-
|
Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Clou…
|
CWE-228
Improper Handling of Syntactically Invalid Structure
|
CVE-2026-42100
|
2026-05-19 23:45 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
766
|
- |
|
-
|
-
|
Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves…
|
CWE-362
Race Condition
|
CVE-2026-42099
|
2026-05-19 23:45 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
767
|
3.9 |
LOW
Local
|
-
|
-
|
FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The app…
|
CWE-79
Cross-site Scripting
|
CVE-2026-27964
|
2026-05-19 23:44 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
768
|
6.5 |
MEDIUM
Network
|
-
|
-
|
FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC meta…
|
CWE-200 CWE-212
Information Exposure Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2026-27892
|
2026-05-19 23:44 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
769
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unpriv…
|
CWE-200 CWE-524 CWE-672
Information Exposure Use of Cache Containing Sensitive Information Operation on a Resource after Expiration or Release
|
CVE-2026-32244
|
2026-05-19 23:44 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
770
|
- |
|
-
|
-
|
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature…
|
CWE-862
Missing Authorization
|
CVE-2026-33514
|
2026-05-19 23:44 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|