|
3351
|
3.5 |
LOW
Network
|
-
|
-
|
Se determinó una vulnerabilidad en wandb OpenUI hasta la versión 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo frontend/public/annotator/index.html del componente…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4995
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3352
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.98.1 due to insufficient input sanitization and output…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2595
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3353
|
5.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Quads Ads Manager para Google AdSense para WordPress es vulnerable a cross-site scripting almacenado en versiones hasta la 2.0.98.1, inclusive, debido a una sanitización de entrada y un esc…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2595
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3354
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_ques…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4996
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3355
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en Sinaptik AI PandasAI hasta 0.1.4. Afectada por este problema es la función delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_releva…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4996
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3356
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results i…
|
CWE-22
Path Traversal
|
CVE-2026-4997
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3357
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en Sinaptik AI PandasAI hasta 3.0.0. Esto afecta a la función is_sql_query_safe del archivo pandasai/helpers/sql_sanitizer.py. Realizar una manipulación res…
|
CWE-22
Path Traversal
|
CVE-2026-4997
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3358
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the compo…
|
CWE-74 CWE-94
Injection Code Injection
|
CVE-2026-4998
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3359
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha identificado una debilidad en Sinaptik AI PandasAI hasta la versión 3.0.0. Esta vulnerabilidad afecta a la función CodeExecutor.execute del archivo pandasai/core/code_execution/code_executor.py…
|
CWE-74 CWE-94
Injection Code Injection
|
CVE-2026-4998
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3360
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file src/index.ts of the component add_git_repository/add_text_file. The manipulatio…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5007
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|