|
231
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-30812
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
7.5 |
HIGH
Network
|
-
|
-
|
Nitro PDF Pro for Windows 14.41.1.4 contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the f…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-69624
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 777 through 800
Update
|
CWE-89
SQL Injection
|
CVE-2026-30813
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 777 through 800
Update
|
CWE-89
SQL Injection
|
CVE-2026-34186
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800
Update
|
CWE-78
OS Command
|
CVE-2026-34188
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
- |
|
-
|
-
|
Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker t…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-23891
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
4.0 |
MEDIUM
Network
|
-
|
-
|
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame wit…
Update
|
CWE-130
Improper Handling of Length Parameter Inconsistency
|
CVE-2026-33555
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
8.8 |
HIGH
Network
|
-
|
-
|
The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` parameter to execute sh…
Update
|
CWE-94
Code Injection
|
CVE-2026-29955
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
8.1 |
HIGH
Network
|
-
|
-
|
simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks mean…
Update
|
CWE-78
OS Command
|
CVE-2026-28291
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
8.2 |
HIGH
Network
|
-
|
-
|
jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strin…
Update
|
CWE-122 CWE-190
Heap-based Buffer Overflow Integer Overflow or Wraparound
|
CVE-2026-32316
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|