|
521
|
8.4 |
HIGH
Local
|
-
|
-
|
10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering …
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2018-25344
|
2026-05-24 04:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
522
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft H…
|
CWE-352
Origin Validation Error
|
CVE-2018-25343
|
2026-05-24 04:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
523
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in sear…
|
CWE-89
SQL Injection
|
CVE-2018-25342
|
2026-05-24 04:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
524
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET …
|
CWE-89
SQL Injection
|
CVE-2018-25341
|
2026-05-24 04:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
525
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET …
|
CWE-89
SQL Injection
|
CVE-2018-25340
|
2026-05-24 04:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
526
|
3.7 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjou…
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-9306
|
2026-05-24 01:19 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
527
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. Th…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9305
|
2026-05-24 00:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
528
|
5.0 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The ma…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-9304
|
2026-05-23 23:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
529
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Th…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-9303
|
2026-05-23 23:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
530
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of …
|
CWE-74 CWE-94
Injection Code Injection
|
CVE-2026-9302
|
2026-05-23 23:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|