|
4101
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en mickasmt next-saas-stripe-starter 1.0.0. Afectada por esta vulnerabilidad es la función updateUserrole del archivo actions/update-user-role.ts. La manipulación del…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-4548
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4102
|
3.1 |
LOW
Network
|
-
|
-
|
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. Th…
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-4549
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4103
|
3.1 |
LOW
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en mickasmt next-saas-stripe-starter 1.0.0. Afectada por este problema es la función openCustomerPortal del archivo actions/open-customer-portal.ts del componente …
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-4549
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4104
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname lead…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4550
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4105
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en code-projects Simple Gym Management System hasta la versión 1.0. Esto afecta una parte desconocida del archivo /gym/func.php. Dicha manipulación del argumento…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4550
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4106
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in c…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4557
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4107
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en code-projects Exam Form Submission 1.0. Esto impacta una función desconocida del archivo /admin/update_s1.php. Realizar una manipulación del argumento sname result…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4557
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4108
|
7.5 |
HIGH
Network
|
-
|
-
|
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up …
|
CWE-89
SQL Injection
|
CVE-2026-2580
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4109
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'orderby' en to…
|
CWE-89
SQL Injection
|
CVE-2026-2580
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4110
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation r…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-4562
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|