Vulnerabilities (CVE)

Angry Yack Logo
Total 336347 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26892 1 Oretnom23 1 Simple Logistic Hub Parcel\'s Management System 2026-03-05 N/A 7.2 HIGH
Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.
CVE-2026-28546 1 Huawei 1 Harmonyos 2026-03-05 N/A 5.9 MEDIUM
Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-3136 1 Google 1 Cloud Build 2026-03-05 N/A 9.8 CRITICAL
An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was patched on 26 January 2026, and no customer action is needed.
CVE-2026-28547 1 Huawei 1 Harmonyos 2026-03-05 N/A 6.8 MEDIUM
Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28548 1 Huawei 2 Emui, Harmonyos 2026-03-05 N/A 7.1 HIGH
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-66680 1 Wisecleaner 1 Wise Force Deleter 2026-03-05 N/A 7.1 HIGH
An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files via a crafted request.
CVE-2026-28549 1 Huawei 1 Harmonyos 2026-03-05 N/A 6.6 MEDIUM
Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-24103 1 Tenda 2 Ac15, Ac15 Firmware 2026-03-05 N/A 9.8 CRITICAL
A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.
CVE-2026-28551 1 Huawei 1 Harmonyos 2026-03-05 N/A 4.7 MEDIUM
Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-70821 1 Renren 1 Renren-security 2026-03-05 N/A 9.8 CRITICAL
renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
CVE-2026-28542 1 Huawei 2 Emui, Harmonyos 2026-03-05 N/A 7.3 HIGH
Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28552 1 Huawei 2 Emui, Harmonyos 2026-03-05 N/A 6.5 MEDIUM
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28550 1 Huawei 1 Harmonyos 2026-03-05 N/A 4.0 MEDIUM
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28545 1 Huawei 1 Harmonyos 2026-03-05 N/A 5.9 MEDIUM
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28544 1 Huawei 1 Harmonyos 2026-03-05 N/A 6.2 MEDIUM
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28543 1 Huawei 1 Harmonyos 2026-03-05 N/A 4.4 MEDIUM
Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28541 1 Huawei 1 Harmonyos 2026-03-05 N/A 4.0 MEDIUM
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28540 1 Huawei 1 Harmonyos 2026-03-05 N/A 4.0 MEDIUM
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-28539 1 Huawei 1 Harmonyos 2026-03-05 N/A 6.2 MEDIUM
Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-28538 1 Huawei 1 Harmonyos 2026-03-05 N/A 5.9 MEDIUM
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-3437 1 Portwell 1 Engineering Toolkits 2026-03-05 N/A 7.8 HIGH
An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.
CVE-2026-3484 1 Phialsbasement 1 Mcp Nmap Server 2026-03-05 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identi ...

Show More

CVE-2026-2201 1 Zerowdd 1 Studentmanager 2026-03-05 3.3 LOW 2.4 LOW
A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanager/controller/LeaveController.java. The manipulation of the argument Reason for Leave leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, spec ...

Show More

CVE-2026-2178 1 R-huijts 1 Xcode Mcp Server 2026-03-05 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the argument args results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affecte ...

Show More

CVE-2026-2153 1 Mwielgoszewski 1 Doorman 2026-03-05 5.0 MEDIUM 4.3 MEDIUM
A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-1567 1 Ibm 1 Infosphere Information Server 2026-03-05 N/A 7.1 HIGH
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.
CVE-2025-14480 1 Ibm 1 Aspera Faspio Gateway 2026-03-05 N/A 5.1 MEDIUM
IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
CVE-2026-2145 1 Cym1102 1 Nginxwebui 2026-03-05 4.0 MEDIUM 3.5 LOW
A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of the component Web Management Interface. Such manipulation of the argument nginxDir leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-24502 1 Dell 1 Command \| Intel Vpro Out Of Band 2026-03-05 N/A 8.8 HIGH
Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-25906 1 Dell 1 Optimizer 2026-03-05 N/A 7.3 HIGH
Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
CVE-2026-21866 1 Dify 1 Dify 2026-03-05 N/A 5.4 MEDIUM
Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is fixed in 1.11.2.
CVE-2026-25590 1 Glpi-project 1 Glpi Inventory 2026-03-05 N/A 4.5 MEDIUM
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.
CVE-2026-26266 1 Aliasvault 1 Aliasvault 2026-03-05 N/A 9.3 CRITICAL
AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in an iframe using srcdoc, which does not provide origin isolation. An attacker can send a crafted email containing malicious JavaScript to any AliasVault email alias. When the victim views the email in t ...

Show More

CVE-2026-2141 1 5kcrm 1 Wukongcrm 2026-03-05 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-26272 1 Sysadminsmedia 1 Homebox 2026-03-05 N/A 4.6 MEDIUM
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file types, allowing an authenticated user to upload malicious HTML or SVG files containing executable JavaScript (also, potentially other formats that render scripts). Uploaded attachments are accessible via direct links. When a user accesses such a file in ...

Show More

CVE-2026-26279 1 Froxlor 1 Froxlor 2026-03-05 N/A 9.1 CRITICAL
Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adminmail setting. This value is later concatenated into a shell command executed as root by a cron job, where the pipe character | is explicitly whitelisted. The result is full root-level Remote Code Exe ...

Show More

CVE-2026-29188 2026-03-05 N/A 9.1 CRITICAL
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access control vulnerability in the TUS protocol DELETE endpoint allows authenticated users with only Create permission to delete arbitrary files and directories within their scope, bypassing the intended Delete permission restriction. Any multi-user deployment where administrators explicitly restrict file deletion fo ...

Show More

CVE-2026-29081 2026-03-05 N/A 6.5 MEDIUM
Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This issue has been patched in versions 14.100.1 and 15.100.0.
CVE-2026-29077 2026-03-05 N/A 7.1 HIGH
Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user could share a document with a permission that they themselves didn't have. This issue has been patched in versions 15.98.0 and 14.100.0.
CVE-2026-28492 2026-03-05 N/A N/A
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.0, when a user creates a public share link for a directory, the withHashFile middleware in http/public.go uses filepath.Dir(link.Path) to compute the BasePathFs root. This sets the filesystem root to the parent directory instead of the shared directory itself, allowing anyone with the share link to browse and download files from ...

Show More