🌐

Web Application

slug: web-application

🛡 Vulnérabilités associées 283

ID Titre
CVE-2026-57955 SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers...
CVE-2026-57947 Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook...
CVE-2026-57950 ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
CVE-2026-56780 Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api...
CVE-2026-56285 Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
CVE-2026-13521 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php....
CVE-2026-13498 A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an...
CVE-2026-58054 MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
CVE-2026-58056 RustDesk gates incoming control messages on per-capability flags rather than on the session's...
CVE-2026-3652 The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value`...
CVE-2026-54639 Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-10521 An high privileged remote attacker can access a hidden configuration method, that should not be...
CVE-2026-9029 The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug....
CVE-2026-42129 The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An...
CVE-2026-53866 OpenClaw: Shell inline-command parsing could miss an allowlist check
CVE-2026-53864 OpenClaw: Host environment sanitizer missed two Node.js control variables
CVE-2026-53857 OpenClaw: Zalo allowFrom could bind to mutable display names
CVE-2026-53849 OpenClaw: Discord allowFrom could bind to mutable display names
CVE-2026-53855 OpenClaw: Shell positional parameters could weaken strict inline-eval checks
CVE-2026-53843 OpenClaw: Pairing-scoped device session could restore revoked node token authority
CVE-2026-53705 Vulnérabilité dans CVE-2026-53705 (CVE-2026-53705)
CVE-2026-41708 Vulnérabilité dans dos (CVE-2026-41708)
CVE-2026-53782 @steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
CVE-2026-46489 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG f...
CVE-2026-46622 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any...
CVE-2026-47170 Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HT...
CVE-2026-45541 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation pat...
CVE-2026-47906 Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
CVE-2026-11501 A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System...
CVE-2026-11488 A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This...

🍪 À propos des cookies

Nous utilisons des cookies pour conserver votre session, mémoriser la langue et améliorer le service.

En savoir plus →