|
2501
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) t…
|
CWE-94
Code Injection
|
CVE-2026-6951
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2502
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The manipulation leads to improper authorizati…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-6977
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2503
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sq…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6978
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2504
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes serve…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6979
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2505
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6983
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2506
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The mani…
|
CWE-791 CWE-1336
Incomplete Filtering of Special Elements Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-6984
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2507
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument Nome/Descriçã…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6990
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2508
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Exec…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6991
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2509
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipula…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6995
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2510
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can le…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6996
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|