Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 398 253

Количество 398 253

nvd логотип

CVE-2026-5640

6 месяцев назад

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-56409

3 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56408

3 месяца назад

libexpat before 2.8.2 has an integer overflow in copyString.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56407

3 месяца назад

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56406

3 месяца назад

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56405

3 месяца назад

libexpat before 2.8.2 has an integer overflow in getAttributeId.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56404

3 месяца назад

libexpat before 2.8.2 has an integer overflow in addBinding.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56403

3 месяца назад

libexpat before 2.8.2 has an integer overflow in storeAtts.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56402

3 месяца назад

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56401

3 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
nvd логотип

CVE-2026-56400

2 месяца назад

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-5639

6 месяцев назад

A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-56399

3 месяца назад

Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services and potentially execute commands via instance secrets.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2026-56398

2 месяца назад

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-56397

3 месяца назад

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2026-56396

3 месяца назад

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56395

3 месяца назад

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

EPSS: Низкий
nvd логотип

CVE-2026-56394

3 месяца назад

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56393

3 месяца назад

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated administrator (with allowAdminChanges enabled) can inject malicious payloads into section names, volume names, user group names, global set names, generated field names, checkbox/radio option labels, and custom source labels, causing arbitrary JavaScript to execute in other users' control-panel sessions. Fixed in 4.17.0-beta.1 and 5.9.0-beta.1.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-56392

2 месяца назад

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5640

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56409

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56408

libexpat before 2.8.2 has an integer overflow in copyString.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56407

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56406

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56405

libexpat before 2.8.2 has an integer overflow in getAttributeId.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56404

libexpat before 2.8.2 has an integer overflow in addBinding.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56403

libexpat before 2.8.2 has an integer overflow in storeAtts.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56402

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56401

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

3 месяца назад
nvd логотип
CVE-2026-56400

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

CVSS3: 8.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5639

A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56399

Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services and potentially execute commands via instance secrets.

CVSS3: 5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56398

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.

CVSS3: 7.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56397

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

CVSS3: 9.6
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56396

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.

CVSS3: 8.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56395

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

3 месяца назад
nvd логотип
CVE-2026-56394

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56393

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated administrator (with allowAdminChanges enabled) can inject malicious payloads into section names, volume names, user group names, global set names, generated field names, checkbox/radio option labels, and custom source labels, causing arbitrary JavaScript to execute in other users' control-panel sessions. Fixed in 4.17.0-beta.1 and 5.9.0-beta.1.

CVSS3: 4.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56392

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

CVSS3: 6.1
0%
Низкий
2 месяца назад

Уязвимостей на страницу