|
2581
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha identificado una debilidad en el sistema de pedidos de comida en línea code-projects 1.0. Esto afecta una parte desconocida del archivo form/cart.PHP del componente Módulo de Carrito de Compras…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4841
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2582
|
8.8 |
HIGH
Network
|
-
|
-
|
Se ha descubierto una vulnerabilidad de seguridad en Netcore Power 15AX hasta la versión 3.0.0.6938. Afectada por este problema es la función setTools del archivo /bin/netis.cgi del componente Diagno…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4840
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2583
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/grades/index.php?view=edit&id=1 of the component Para…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4842
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2584
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en itsourcecode Online Enrollment System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /sms/grades/index.php?view=edit&id=1 del …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4842
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2585
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin.php of the component Admin Login Module. The manipulation …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4844
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2586
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en code-projects Online Food Ordering System 1.0. Este problema afecta algún procesamiento desconocido del archivo /admin.php del componente Módulo de Inicio de Sesió…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4844
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2587
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic erro…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-1206
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2588
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Elementor Website Builder para WordPress es vulnerable a una Autorización Incorrecta que conduce a la Exposición de Información Sensible en todas las versiones hasta la 3.35.7, inclusive. E…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-1206
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2589
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/index.html. This manipulation of the argument Search causes cross site scripting. I…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4845
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2590
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado un fallo en dameng100 muucmf 1.9.5.20260309. Afecta a una función desconocida del archivo /admin/Member/index.html. Esta manipulación del argumento Search causa cross-site scripting.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4845
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|