|
2521
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en la Plataforma de Gestión Integrada Tiandy Easy7 hasta la versión 7.17.0. Esta vulnerabilidad afecta a código desconocido del archivo /Easy7/apps/WebService/Impo…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4585
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2522
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/server/web…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4586
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2523
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue encontrada en CodePhiliaX Chat2DB hasta 0.3.7. Esto afecta la función Upload del archivo chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/serve…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4586
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2524
|
3.7 |
LOW
Network
|
-
|
-
|
Una vulnerabilidad fue encontrada en HybridAuth hasta la versión 3.12.2. Este problema afecta a algún procesamiento desconocido del archivo src/HttpClient/Curl.php del componente Gestor SSL. La manip…
|
CWE-287 CWE-295
Improper Authentication Improper Certificate Validation
|
CVE-2026-4587
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2525
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-le…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-4588
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2526
|
3.7 |
LOW
Network
|
-
|
-
|
Se determinó una vulnerabilidad en kalcaddle kodbox 1.64. La función shareSafeGroup del archivo /workspace/source-code/app/controller/explorer/shareOut.class.php del componente Gestor de clave API a …
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-4588
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2527
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/source-code/plugins/fileThumb/app.php of the component fileThumb Endpoint. Executing…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4591
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2528
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the co…
|
CWE-89 CWE-564
SQL Injection SQL Injection: Hibernate
|
CVE-2026-4593
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2529
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una falla en erupts erupt bis 1.13.3. Afectada por esta vulnerabilidad es la función EruptDataQuery del archivo erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java del …
|
CWE-89 CWE-564
SQL Injection SQL Injection: Hibernate
|
CVE-2026-4593
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2530
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en kalcaddle kodbox 1.64. El elemento afectado es la función PathDriverUrl del archivo /workspace/source-code/app/controller/explorer/editor.class.PHP del componen…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4589
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|