|
2621
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s7.php. This manipulation of the argument sname causes cross site …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4909
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2622
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function sitemap.fetch of the file /sitemap of the component En…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4907
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2623
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en Page-Replica Page Replica hasta e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. El elemento impactado es la función sitemap.fetch del archivo /sitemap del componente …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4907
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2624
|
2.4 |
LOW
Network
|
-
|
-
|
Se ha identificado una debilidad en code-projects Exam Form Submission 1.0/7.PHP. Esto afecta una función desconocida del archivo /admin/update_s7.PHP. Esta manipulación del argumento sname causa cro…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4909
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2625
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticate…
|
CWE-862
Missing Authorization
|
CVE-2026-3098
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2626
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Smart Slider 3 para WordPress es vulnerable a la lectura arbitraria de archivos en todas las versiones hasta la 3.5.1.33, inclusive, a través de la función 'actionExportAll'. Esto permite a…
|
CWE-862
Missing Authorization
|
CVE-2026-3098
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2627
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such ma…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4910
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2628
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en Shenzhen Ruiming Technology Streamax Crocus bis 1.3.44. Afectada es una función desconocida del archivo /RemoteFormat.do del componente Endpoint. …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4910
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2629
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4953
|
2026-04-25 01:35 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2630
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List End…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4954
|
2026-04-25 01:35 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|