|
531
|
2.4 |
LOW
Network
|
-
|
-
|
A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scrip…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7014
|
2026-04-28 03:46 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
532
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_emai…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7015
|
2026-04-28 03:46 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
533
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7016
|
2026-04-28 03:46 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
534
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/…
New
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-7018
|
2026-04-28 03:46 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
535
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/servlet/file/DeleteFileServl…
New
|
CWE-22
Path Traversal
|
CVE-2026-7024
|
2026-04-28 03:46 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
536
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The manipulation leads to improper authorizati…
Update
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-6977
|
2026-04-28 03:42 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
537
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sq…
Update
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6978
|
2026-04-28 03:42 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
538
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes serve…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6979
|
2026-04-28 03:42 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
539
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of the file main.py. Such manipulation of the argumen…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6980
|
2026-04-28 03:42 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
540
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of th…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6981
|
2026-04-28 03:42 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|