|
1511
|
3.5 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5252
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1512
|
3.5 |
LOW
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en z-9527 admin 1.0/2.0. Afectada es una función desconocida del archivo /servidor/routes/message.js del componente Message Create Endpoint. Realizar una ma…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5252
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1513
|
3.5 |
LOW
Network
|
-
|
-
|
A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component edi…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5253
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1514
|
3.5 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5254
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1515
|
3.5 |
LOW
Network
|
-
|
-
|
Se ha identificado una debilidad en bufanyun HotGo 1.0/2.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /web/src/layout/components/Header/MessageList.vue del compone…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5253
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1516
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the…
|
CWE-22
Path Traversal
|
CVE-2026-5258
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1517
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/contro…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5259
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1518
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base/BaseHandler.ashx. The manipulation of the argumen…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5261
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1519
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a man…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-1879
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1520
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to deni…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-5313
|
2026-04-25 03:12 |
2026-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|