|
31
|
6.1 |
MEDIUM
Network
|
-
|
-
|
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can ind…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44227
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
5.3 |
MEDIUM
Network
|
-
|
-
|
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker c…
New
|
CWE-204
Response Discrepancy Information Exposure
|
CVE-2026-42218
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
- |
|
-
|
-
|
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with know…
New
|
CWE-287
Improper Authentication
|
CVE-2026-42210
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
- |
|
-
|
-
|
In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the VFS `/etemplates` m…
New
|
CWE-78 CWE-95
OS Command Eval Injection
|
CVE-2026-40187
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-39878
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
- |
|
-
|
-
|
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-35591
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, t…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-35048
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
- |
|
-
|
-
|
Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`…
New
|
CWE-285
Improper Authorization
|
CVE-2026-34239
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
7.3 |
HIGH
Network
|
-
|
-
|
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…
New
|
CWE-601
Open Redirect
|
CVE-2026-32824
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
6.1 |
MEDIUM
Network
|
-
|
-
|
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…
New
|
CWE-80
Basic XSS
|
CVE-2026-32822
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|