Recent
Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool
Published 2026-09-21 by GitHub_M
Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation
Published 2026-09-21 by GitHub_M
lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource
Published 2026-09-21 by VulnCheck
lamp-cloud through 5.10.0 Unauthorized Notification Deletion
Published 2026-09-21 by VulnCheck
lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints
Published 2026-09-21 by VulnCheck
lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file
Published 2026-09-21 by VulnCheck
lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById
Published 2026-09-21 by VulnCheck
Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint
Published 2026-09-21 by VulnCheck
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
Published 2026-09-21 by GitHub_M
Discourse: Stored XSS via unescaped actor name in post actions
Published 2026-09-21 by GitHub_M
Load more ↓