Overview
- SourceCodester
- Simple Responsive Tourism Website
08 Mar 2026
Published
08 Mar 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
0.05%
KEV
Description
A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Statistics
- 1 Post
Last activity: 13 hours ago
Overview
- stellarwp
- The Events Calendar
10 Mar 2026
Published
10 Mar 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.06%
KEV
Description
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Statistics
- 1 Post
Last activity: 19 hours ago
Fediverse
๐จ CVE-2026-3585 (HIGH): Path traversal in stellarwp The Events Calendar plugin lets Author+ users read any files on WordPress servers up to v6.15.17. Restrict access, monitor logs, and patch ASAP. Details: https://radar.offseq.com/threat/cve-2026-3585-cwe-22-improper-limitation-of-a-path-57fec669 #OffSeq #WordPress #Vuln #Cybersecurity
Overview
- Siemens
- SINEC Security Monitor
08 Oct 2024
Published
10 Mar 2026
Updated
CVSS v3.1
CRITICAL (9.9)
EPSS
2.95%
KEV
Description
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command.
This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Zsoft
- OOP CMS BLOG
06 Mar 2026
Published
09 Mar 2026
Updated
CVSS v4.0
HIGH (8.8)
EPSS
0.06%
KEV
Description
OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to extract database information including table names, schema names, and database credentials.
Statistics
- 1 Post
Last activity: 21 hours ago
Overview
Description
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
Statistics
- 1 Post
Last activity: 15 hours ago
Overview
Description
PHPads 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the bannerID parameter in click.php3. Attackers can submit crafted bannerID values using SQL comment syntax and functions like extractvalue to extract sensitive database information such as the current database name.
Statistics
- 1 Post
Last activity: 9 hours ago
Overview
Description
Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
Statistics
- 2 Posts
Last activity: 10 hours ago
Bluesky
๐จ #Fedora 43: Chromium 145.0.7632.159 patches 10 CVEs (CVE-2026-3536 to 3545). Critical fixes for ANGLE, Skia, V8, and WebAssembly. Read more: ๐ tinyurl.com/3xnkfshe #Security
Overview
Description
Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user could share a document with a permission that they themselves didn't have. This issue has been patched in versions 15.98.0 and 14.100.0.
Statistics
- 1 Post
Last activity: 10 hours ago
Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 1 Post
Last activity: 8 hours ago
Overview
- Copeland
- Copeland XWEB 300D PRO
27 Feb 2026
Published
03 Mar 2026
Updated
CVSS v3.1
HIGH (8.0)
EPSS
0.26%
KEV
Description
An OS command injection
vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an
authenticated attacker to achieve remote code execution on the system by
injecting malicious input into the devices field of the firmware update
apply action.
Statistics
- 1 Post
Last activity: 20 hours ago