|
1061
|
- |
|
-
|
-
|
Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-25714
|
2026-04-23 06:20 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1062
|
- |
|
-
|
-
|
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a mali…
|
CWE-79
Cross-site Scripting
|
CVE-2026-41456
|
2026-04-23 06:20 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1063
|
6.3 |
MEDIUM
Network
|
-
|
-
|
nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an arbitrary existing directory on disk by manipulati…
|
CWE-22
Path Traversal
|
CVE-2026-6829
|
2026-04-23 06:20 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1064
|
3.3 |
LOW
Local
|
-
|
-
|
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next pr…
|
CWE-459 CWE-668
Incomplete Cleanup Exposure of Resource to Wrong Sphere
|
CVE-2026-6830
|
2026-04-23 06:20 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1065
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context of a u…
|
CWE-79
Cross-site Scripting
|
CVE-2026-30139
|
2026-04-23 06:18 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1066
|
8.7 |
HIGH
Adjacent
|
-
|
-
|
Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these p…
|
CWE-1104
Use of Unmaintained Third Party Components
|
CVE-2026-41468
|
2026-04-23 06:18 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1067
|
5.2 |
MEDIUM
Adjacent
|
-
|
-
|
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-41469
|
2026-04-23 06:18 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1068
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a lack of protocol validation in the FileBlock compon…
|
CWE-79
Cross-site Scripting
|
CVE-2026-35451
|
2026-04-23 06:17 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1069
|
9.4 |
CRITICAL
Network
|
-
|
-
|
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or S…
|
CWE-22
Path Traversal
|
CVE-2026-40576
|
2026-04-23 06:17 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1070
|
8.8 |
HIGH
Network
|
-
|
-
|
Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A ma…
|
CWE-22
Path Traversal
|
CVE-2026-40611
|
2026-04-23 06:17 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|