|
2531
|
3.1 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the compo…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-4590
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2532
|
3.1 |
LOW
Network
|
-
|
-
|
Se ha descubierto una vulnerabilidad de seguridad en kalcaddle kodbox 1.64. El elemento afectado es una función desconocida del archivo /workspace/source-code/plugins/oauth/controller/bind/index.clas…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-4590
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2533
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Se ha identificado una debilidad en kalcaddle kodbox 1.64. Esto afecta a la función checkBin del archivo /workspace/source-code/plugins/fileThumb/app.PHP del componente fileThumb Endpoint. Ejecutar u…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4591
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2534
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of…
|
CWE-287
Improper Authentication
|
CVE-2026-4592
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2535
|
5.6 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en kalcaddle kodbox 1.64. Esto afecta la función loginAfter/tfaVerify del archivo /workspace/source-code/plugins/client/controller/tfa/index.class.ph…
|
CWE-287
Improper Authentication
|
CVE-2026-4592
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2536
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy of the file erupt-data/erupt-jpa/src/main/java/xyz/erupt/jpa/dao/EruptJpaUtils.…
|
CWE-89 CWE-564
SQL Injection SQL Injection: Hibernate
|
CVE-2026-4594
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2537
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was determined in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the file /admin/update_s6.php. Executing a manipulation of the argument sname can …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4595
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2538
|
2.4 |
LOW
Network
|
-
|
-
|
Se determinó una vulnerabilidad en code-projects Exam Form Submission 1.0. Esta vulnerabilidad afecta código desconocido del archivo /admin/update_s6.php. La ejecución de una manipulación del argumen…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4595
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2539
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en erupts erupt hasta la versión 1.13.3. Afectada por este problema es la función geneEruptHqlOrderBy del archivo erupt-data/erupt-jpa/src/main/java/xyz/erupt/jp…
|
CWE-89 CWE-564
SQL Injection SQL Injection: Hibernate
|
CVE-2026-4594
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2540
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. Impacted is the function selectAll of the file src/main/java/com/genersoft/iot/vmp/streamProxy/dao/provider/StreamProxyPr…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4597
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|