|
331
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of the component URL Fetching. Executing a manipulation of the argument fileUrl can…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7291
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAgent. The manipulation leads to improper authorizati…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-7292
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of the file /admin/ajax.php?action=delete_category. The manipulation of the argum…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7293
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
2.4 |
LOW
Network
|
-
|
-
|
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_settings. This manipulation o…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7294
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the …
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7295
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7296
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7297
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
3.7 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.jav…
New
|
CWE-99
Resource Injection
|
CVE-2026-7303
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7305
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument docume…
New
|
CWE-22
Path Traversal
|
CVE-2026-7314
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|