|
501
|
5.0 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/about/downloadApp.ts of the component downloadApp End…
New
|
CWE-22
Path Traversal
|
CVE-2026-7085
|
2026-04-28 03:50 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
502
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl of the file replaceUrl.ts of the component Storyboard Export. Such manipulatio…
New
|
CWE-22
Path Traversal
|
CVE-2026-7086
|
2026-04-28 03:50 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
503
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulat…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7037
|
2026-04-28 03:50 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
504
|
3.3 |
LOW
Local
|
-
|
-
|
A weakness has been identified in tufantunc ssh-mcp up to 1.5.0. Impacted is an unknown function of the file src/index.ts of the component Command Line Handler. This manipulation causes insufficientl…
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-7038
|
2026-04-28 03:50 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
505
|
7.8 |
HIGH
Local
|
-
|
-
|
A security vulnerability has been detected in tufantunc ssh-mcp up to 1.5.0. The affected element is the function shell.write of the file src/index.ts. Such manipulation of the argument Description l…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7039
|
2026-04-28 03:50 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
506
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in 666ghj MiroFish up to 0.1.2. The impacted element is an unknown function of the file /console of the component Werkzeug Debugger PIN Handler. Performing a manipulation…
New
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-7041
|
2026-04-28 03:50 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
507
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST API Endpoint. Executing a manipulation can lead to…
New
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-7042
|
2026-04-28 03:50 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
508
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The …
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-7043
|
2026-04-28 03:50 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
509
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can …
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-7044
|
2026-04-28 03:50 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
510
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spri…
New
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-7045
|
2026-04-28 03:50 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|