|
2011
|
7.1 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Sid…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41272
|
2026-04-25 01:37 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2012
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /admin/mod_room/index.php?view=edit. Executing a manipulation of the argument ID c…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4966
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2013
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-4968
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2014
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the a…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4969
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2015
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4970
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2016
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack is possible to be carried…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-4971
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2017
|
2.4 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.ph…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4972
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2018
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulatio…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4973
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2019
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the file src/cgif.c of the component GIF Image Handler. The manipulation of the arg…
|
CWE-189 CWE-190
Numeric Errors Integer Overflow or Wraparound
|
CVE-2026-4985
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2020
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argu…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-4990
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|