|
2441
|
2.4 |
LOW
Network
|
-
|
-
|
Se ha identificado una debilidad en code-projects Exam Form Submission 1.0/7.PHP. Esto afecta una función desconocida del archivo /admin/update_s7.PHP. Esta manipulación del argumento sname causa cro…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4909
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2442
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticate…
|
CWE-862
Missing Authorization
|
CVE-2026-3098
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2443
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Smart Slider 3 para WordPress es vulnerable a la lectura arbitraria de archivos en todas las versiones hasta la 3.5.1.33, inclusive, a través de la función 'actionExportAll'. Esto permite a…
|
CWE-862
Missing Authorization
|
CVE-2026-3098
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2444
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such ma…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4910
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2445
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en Shenzhen Ruiming Technology Streamax Crocus bis 1.3.44. Afectada es una función desconocida del archivo /RemoteFormat.do del componente Endpoint. …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4910
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2446
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4953
|
2026-04-25 01:35 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2447
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List End…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4954
|
2026-04-25 01:35 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2448
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. The manipulation of the argument VehicleID results …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4955
|
2026-04-25 01:35 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2449
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePrint.do?Action=ReadTask of the component Parameter …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4956
|
2026-04-25 01:35 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2450
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py. Performing a manipulation of the argument D…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4530
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|