|
2631
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. The manipulation of the argument VehicleID results …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4955
|
2026-04-25 01:35 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2632
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePrint.do?Action=ReadTask of the component Parameter …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4956
|
2026-04-25 01:35 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2633
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py. Performing a manipulation of the argument D…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4530
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2634
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Se ha descubierto una falla de seguridad en apconw Aix-DB hasta 1.2.3. Esto afecta una función desconocida del archivo agent/text2sql/rag/terminology_retriever.py. Realizar una manipulación del argum…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4530
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2635
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to den…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-4531
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2636
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Se ha identificado una debilidad en Free5GC 4.1.0. Afecta a la función HandleRegistrationComplete del archivo internal/gmm/handler.go del componente AMF. La ejecución de una manipulación puede conduc…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-4531
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2637
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `jsonText` block attribute in all versions up to, an…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3427
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2638
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Yoast SEO – Advanced SEO con guía en tiempo real e IA integrada para WordPress es vulnerable a cross-site scripting almacenado a través del atributo de bloque 'jsonText' en todas las versio…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3427
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2639
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may …
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4536
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2640
|
7.3 |
HIGH
Network
|
-
|
-
|
Se encontró una vulnerabilidad en Acrel Environmental Monitoring Cloud Platform 1.1.0. Este problema afecta algún procesamiento desconocido. Realizar una manipulación resulta en una carga sin restric…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4536
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|