Aggregator
CVE-2022-0664 | gravitl netmaker up to 0.8.4/0.9.3 hard-coded key
1 hour 31 minutes ago
A vulnerability, which was classified as critical, has been found in gravitl netmaker up to 0.8.4/0.9.3. This affects an unknown function. The manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is referenced as CVE-2022-0664. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2022-23650 | Netmaker up to 0.8.4/0.9.3 hard-coded key (GHSA-86f3-hf24-76q4)
1 hour 31 minutes ago
A vulnerability was found in Netmaker up to 0.8.4/0.9.3. It has been classified as critical. This affects an unknown function. Performing a manipulation results in use of hard-coded cryptographic key
.
This vulnerability was named CVE-2022-23650. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2022-36110 | gravitl Netmaker up to 0.15.0 API improper authorization (GHSA-ggf6-638m-vqmg)
1 hour 31 minutes ago
A vulnerability marked as critical has been reported in gravitl Netmaker up to 0.15.0. This impacts an unknown function of the component API. This manipulation causes improper authorization.
This vulnerability is handled as CVE-2022-36110. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2022-45088 | Group Arge Energy and Control Systems Smartpower Web prior 23.01.01 file inclusion
1 hour 31 minutes ago
A vulnerability described as problematic has been identified in Group Arge Energy and Control Systems Smartpower Web. This vulnerability affects unknown code. Such manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2022-45088. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2022-45085 | Group Arge Energy and Control Systems Smartpower Web prior 23.01.01 server-side request forgery
1 hour 31 minutes ago
A vulnerability classified as critical has been found in Group Arge Energy and Control Systems Smartpower Web. This issue affects some unknown processing. Performing a manipulation results in server-side request forgery.
This vulnerability was named CVE-2022-45085. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-45086 | Group Arge Energy and Control Systems Smartpower Web prior 23.01.01 cross site scripting
1 hour 31 minutes ago
A vulnerability classified as problematic was found in Group Arge Energy and Control Systems Smartpower Web. Affected by this vulnerability is an unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2022-45086. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2022-45087 | Group Arge Energy and Control Systems Smartpower Web prior 23.01.01 cross site scripting
1 hour 31 minutes ago
A vulnerability, which was classified as problematic, has been found in Group Arge Energy and Control Systems Smartpower Web. Affected by this issue is some unknown functionality. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2022-45087. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2022-45089 | Group Arge Energy and Control Systems Smartpower Web prior 23.01.01 sql injection
1 hour 31 minutes ago
A vulnerability, which was classified as critical, was found in Group Arge Energy and Control Systems Smartpower Web. This affects an unknown part. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2022-45089. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2022-45090 | Group Arge Energy and Control Systems Smartpower Web prior 23.01.01 sql injection
1 hour 31 minutes ago
A vulnerability has been found in Group Arge Energy and Control Systems Smartpower Web and classified as critical. This vulnerability affects unknown code. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2022-45090. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2022-45091 | Group Arge Energy and Control Systems Smartpower Web prior 23.01.01 cross site scripting
1 hour 31 minutes ago
A vulnerability was found in Group Arge Energy and Control Systems Smartpower Web and classified as problematic. This issue affects some unknown processing. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2022-45091. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2022-4557 | Group Arge Energy and Control Systems Smartpower Web prior 23.01.01 sql injection
1 hour 31 minutes ago
A vulnerability was found in Group Arge Energy and Control Systems Smartpower Web. It has been classified as critical. Impacted is an unknown function. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2022-4557. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
当攻击开始“自主决策”,安全体系如何应战?
2 hours 8 minutes ago
科技云报到
CVE-2026-5163 | Mattermost up to 11.5.1 Post Rewrite Endpoint authorization (EUVD-2026-30753)
2 hours 17 minutes ago
A vulnerability categorized as problematic has been discovered in Mattermost up to 11.5.1. This issue affects some unknown processing of the component Post Rewrite Endpoint. Executing a manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2026-5163. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-57282 | ngrok 4.3.3/5.0.0-beta.2 command injection (EUVD-2025-209888)
2 hours 17 minutes ago
A vulnerability was found in ngrok 4.3.3/5.0.0-beta.2. It has been declared as critical. This affects an unknown function. The manipulation results in command injection.
This vulnerability is reported as CVE-2025-57282. The attacker must have access to the local network to execute the attack. No exploit exists.
vuldb.com
CVE-2026-6495 | Ajax Load More Plugin up to 7.8.3 on WordPress cross site scripting (EUVD-2026-30733)
2 hours 17 minutes ago
A vulnerability was found in Ajax Load More Plugin up to 7.8.3 on WordPress and classified as problematic. This affects an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-6495. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-56352 | tinyMQTT 6226ade15bd4f97be2d196352e64dd10937c1962 denial of service (EUVD-2025-209887)
2 hours 17 minutes ago
A vulnerability has been found in tinyMQTT 6226ade15bd4f97be2d196352e64dd10937c1962 and classified as problematic. Impacted is an unknown function. Performing a manipulation results in denial of service.
This vulnerability is cataloged as CVE-2025-56352. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-20685 | Apple Private Cloud Compute Server Software prior 5E290.3 information disclosure (EUVD-2026-30775)
2 hours 17 minutes ago
A vulnerability was found in Apple Private Cloud Compute Server Software and classified as problematic. The affected element is an unknown function. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2026-20685. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-39079 | upsshipping up to 2.4.0 on PrestaShop logs information disclosure (EUVD-2026-30770)
2 hours 17 minutes ago
A vulnerability described as problematic has been identified in upsshipping up to 2.4.0 on PrestaShop. Affected by this vulnerability is an unknown functionality in the library /modules/upsshipping/lib/UPSBaseApi.php of the file /modules/upsshipping/logs/. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2026-39079. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-26462 | Offline Hospital Management System 5.3.0 privilege escalation (EUVD-2026-30773)
2 hours 17 minutes ago
A vulnerability classified as critical has been found in Offline Hospital Management System 5.3.0. Affected by this issue is some unknown functionality. The manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2026-26462. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com