|
2651
|
2.5 |
LOW
Local
|
-
|
-
|
A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulat…
|
CWE-345 CWE-347
Insufficient Verification of Data Authenticity Improper Verification of Cryptographic Signature
|
CVE-2026-4541
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2652
|
2.5 |
LOW
Local
|
-
|
-
|
Se ha encontrado una falla en janmojzis tinyssh hasta 20250501. Afectada es una función desconocida del archivo tinyssh/crypto_sign_ed25519_tinyssh.c del componente Gestor de Firma Ed25519. Esta mani…
|
CWE-345 CWE-347
Insufficient Verification of Data Authenticity Improper Verification of Cryptographic Signature
|
CVE-2026-4541
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2653
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkou…
|
CWE-840
Business Logic Errors
|
CVE-2026-4547
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2654
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en mickasmt next-saas-stripe-starter 1.0.0. Afectada está la función generateUserStripe del archivo actions/generate-user-stripe.ts del componente Ge…
|
CWE-840
Business Logic Errors
|
CVE-2026-4547
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2655
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-4548
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2656
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en mickasmt next-saas-stripe-starter 1.0.0. Afectada por esta vulnerabilidad es la función updateUserrole del archivo actions/update-user-role.ts. La manipulación del…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-4548
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2657
|
3.1 |
LOW
Network
|
-
|
-
|
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. Th…
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-4549
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2658
|
3.1 |
LOW
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en mickasmt next-saas-stripe-starter 1.0.0. Afectada por este problema es la función openCustomerPortal del archivo actions/open-customer-portal.ts del componente …
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-4549
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2659
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname lead…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4550
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2660
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en code-projects Simple Gym Management System hasta la versión 1.0. Esto afecta una parte desconocida del archivo /gym/func.php. Dicha manipulación del argumento…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4550
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|