|
1231
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of the file apps/experimental/tools_webhook/app.py of the component tools_webhook. …
|
CWE-287
Improper Authentication
|
CVE-2026-6635
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1232
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b. Affected is the function Bun.serve of the file buildCache.js of the component API. Performing a manipulati…
|
CWE-22
Path Traversal
|
CVE-2026-6636
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1233
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component Internal Message Module. Performing a manipulation results in cross site scripti…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6648
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1234
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a manipulation of the argument starts can lead to serv…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6649
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1235
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/AppCentre/app_upload.php of the component ZBA File Handler. The manipulation lead…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-6650
|
2026-04-23 05:22 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1236
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item N…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6651
|
2026-04-23 05:22 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1237
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorage Template Handler. Th…
|
CWE-94 CWE-95
Code Injection Eval Injection
|
CVE-2026-6652
|
2026-04-23 05:22 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1238
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results i…
|
CWE-346 CWE-942
Origin Validation Error Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-6662
|
2026-04-23 05:22 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1239
|
8.1 |
HIGH
Network
|
-
|
-
|
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not valid…
|
CWE-22
Path Traversal
|
CVE-2026-6248
|
2026-04-23 05:22 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1240
|
8.1 |
HIGH
Network
|
-
|
-
|
The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files …
|
CWE-22
Path Traversal
|
CVE-2026-5478
|
2026-04-23 05:22 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|