24h | 7d | 30d

Overview

  • Binardat Ltd.
  • 10G08-0800GSM Network Switch

24 Feb 2026
Published
24 Feb 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.02%

KEV

Description

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-27520 - Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded valu... https://www.cyberhub.blog/cves/CVE-2026-27520
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Labcollector
  • LabCollector

20 Feb 2026
Published
24 Feb 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.34%

KEV

Description

LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the user_name parameter of retrieve_password.php to extract sensitive database information without authentication.

Statistics

  • 1 Post

Last activity: 12 hours ago

Bluesky

Profile picture fallback
📌 CVE-2019-25438 - LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting... https://www.cyberhub.blog/cves/CVE-2019-25438
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Zyxel
  • EX3301-T0 firmware

24 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.18%

KEV

Description

A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
📌 CVE-2025-13943 - A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C... https://www.cyberhub.blog/cves/CVE-2025-13943
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • SourceCodester
  • Simple and Nice Shopping Cart Script

25 Feb 2026
Published
25 Feb 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.02%

KEV

Description

A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-3148 - A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. T... https://www.cyberhub.blog/cves/CVE-2026-3148
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • itsourcecode
  • News Portal Project

24 Feb 2026
Published
24 Feb 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.03%

KEV

Description

A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin/edit-category.php. The manipulation of the argument Category results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-3134 - A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin... https://www.cyberhub.blog/cves/CVE-2026-3134
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • openemr
  • openemr

25 Feb 2026
Published
25 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.03%

KEV

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in the OpenEMR order types management system, allowing low-privilege users (such as Receptionist) to add and modify procedure types without proper authorization. This vulnerability is present in the /openemr/interface/orders/types_edit.php endpoint. Version 8.0.0 contains a patch.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-25131 - OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Contr... https://www.cyberhub.blog/cves/CVE-2026-25131
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • itsourcecode
  • News Portal Project

25 Feb 2026
Published
25 Feb 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.03%

KEV

Description

A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-3135 - A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.ph... https://www.cyberhub.blog/cves/CVE-2026-3135
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • parse-community
  • parse-server

04 Oct 2024
Published
04 Oct 2024
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.38%

KEV

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role. This vulnerability is fixed in 6.5.9 and 7.3.0.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
📌 CVE-2024-47183 - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId... https://www.cyberhub.blog/cves/CVE-2024-47183
  • 0
  • 0
  • 0
  • Last hour

Overview

  • openemr
  • openemr

25 Feb 2026
Published
25 Feb 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.01%

KEV

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external HTTPS connections vulnerable to man-in-the-middle (MITM) attacks. This affects communication with government healthcare APIs and user-configurable external services, potentially exposing Protected Health Information (PHI). Version 7.0.4 fixes the issue.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
📌 CVE-2025-67752 - OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client... https://www.cyberhub.blog/cves/CVE-2025-67752
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Tenda
  • F453

25 Feb 2026
Published
25 Feb 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.08%

KEV

Description

A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-3166 - A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the comp... https://www.cyberhub.blog/cves/CVE-2026-3166
  • 0
  • 0
  • 0
  • 21h ago
Showing 31 to 40 of 189 CVEs