Overview
- Binardat Ltd.
- 10G08-0800GSM Network Switch
24 Feb 2026
Published
24 Feb 2026
Updated
CVSS v4.0
HIGH (8.7)
EPSS
0.02%
KEV
Description
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Labcollector
- LabCollector
20 Feb 2026
Published
24 Feb 2026
Updated
CVSS v4.0
HIGH (8.8)
EPSS
0.34%
KEV
Description
LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the user_name parameter of retrieve_password.php to extract sensitive database information without authentication.
Statistics
- 1 Post
Last activity: 12 hours ago
Overview
- Zyxel
- EX3301-T0 firmware
24 Feb 2026
Published
26 Feb 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.18%
KEV
Description
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
- SourceCodester
- Simple and Nice Shopping Cart Script
25 Feb 2026
Published
25 Feb 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
0.02%
KEV
Description
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Statistics
- 1 Post
Last activity: 22 hours ago
Overview
- itsourcecode
- News Portal Project
24 Feb 2026
Published
24 Feb 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
0.03%
KEV
Description
A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin/edit-category.php. The manipulation of the argument Category results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Statistics
- 1 Post
Last activity: 15 hours ago
Overview
Description
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in the OpenEMR order types management system, allowing low-privilege users (such as Receptionist) to add and modify procedure types without proper authorization. This vulnerability is present in the /openemr/interface/orders/types_edit.php endpoint. Version 8.0.0 contains a patch.
Statistics
- 1 Post
Last activity: 21 hours ago
Overview
- itsourcecode
- News Portal Project
25 Feb 2026
Published
25 Feb 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
0.03%
KEV
Description
A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Statistics
- 1 Post
Last activity: 15 hours ago
Overview
- parse-community
- parse-server
04 Oct 2024
Published
04 Oct 2024
Updated
CVSS v3.1
HIGH (8.1)
EPSS
0.38%
KEV
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role. This vulnerability is fixed in 6.5.9 and 7.3.0.
Statistics
- 1 Post
Last activity: Last hour
Overview
Description
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external HTTPS connections vulnerable to man-in-the-middle (MITM) attacks. This affects communication with government healthcare APIs and user-configurable external services, potentially exposing Protected Health Information (PHI). Version 7.0.4 fixes the issue.
Statistics
- 1 Post
Last activity: 18 hours ago
Overview
Description
A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used.
Statistics
- 1 Post
Last activity: 21 hours ago