|
291
|
7.5 |
HIGH
Network
|
-
|
-
|
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remot…
Update
|
CWE-321 CWE-502
Use of Hard-coded Cryptographic Key Deserialization of Untrusted Data
|
CVE-2026-5426
|
2026-04-18 13:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292
|
7.5 |
HIGH
Network
|
-
|
-
|
libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Update
|
CWE-331
Insufficient Entropy
|
CVE-2026-41080
|
2026-04-18 13:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio rang…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-37100
|
2026-04-18 13:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294
|
6.5 |
MEDIUM
Network
|
-
|
-
|
gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP…
New
|
CWE-22
Path Traversal
|
CVE-2026-40491
|
2026-04-18 12:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295
|
7.2 |
HIGH
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37344
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296
|
7.2 |
HIGH
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37343
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297
|
7.2 |
HIGH
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37342
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298
|
7.2 |
HIGH
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37341
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299
|
9.8 |
CRITICAL
Network
|
-
|
-
|
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37340
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300
|
9.8 |
CRITICAL
Network
|
-
|
-
|
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37339
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|