CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-38751 HIGH

OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_module…

CVSS 7.2 EPSS 0.53% May 4, 2026
CVE-2026-35470 HIGH

OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals

CVSS 8.8 EPSS 0.49% Apr 6, 2026
CVE-2026-35168 HIGH

OpenSTAManager: SQL Injection via Aggiornamenti Module

CVSS 8.8 EPSS 0.81% Apr 2, 2026
CVE-2026-28805 HIGH

OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter

CVSS 8.8 EPSS 0.54% Apr 2, 2026
CVE-2026-29782 HIGH

OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2

CVSS 7.2 EPSS 0.69% Apr 2, 2026
CVE-2026-27012 CRITICAL

Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php

CVSS 9.8 EPSS 0.67% Mar 3, 2026
CVE-2026-24415 MEDIUM

OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter

CVSS 5.1 EPSS 0.26% Mar 3, 2026
CVE-2025-69212 CRITICAL

OpenSTAManager has an OS Command Injection in P7M File Processing

CVSS 9.4 EPSS 2.01% Feb 6, 2026
CVE-2025-69214 HIGH

OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)

CVSS 8.7 EPSS 0.44% Feb 6, 2026
CVE-2025-69216 HIGH

OpenSTAManager has an SQL Injection in Scadenzario Print Template

CVSS 8.7 EPSS 0.38% Feb 6, 2026
CVE-2026-24416 HIGH

OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module

CVSS 8.7 EPSS 0.39% Feb 6, 2026
CVE-2026-24417 HIGH

OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

CVSS 8.7 EPSS 0.39% Feb 6, 2026
CVE-2026-24418 HIGH

OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations module

CVSS 8.7 EPSS 0.38% Feb 6, 2026
CVE-2026-24419 HIGH

OpenSTAManager has an SQL Injection in the Prima Nota module

CVSS 8.7 EPSS 0.36% Feb 6, 2026
CVE-2025-69215 HIGH

OpenSTAManager has an SQL Injection in the Stampe Module

CVSS 8.7 EPSS 0.44% Feb 4, 2026
CVE-2025-69213 HIGH

OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)

CVSS 8.7 EPSS 0.44% Feb 4, 2026
CVE-2023-38878 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execute arbitrary JavaS…

CVSS 6.1 EPSS 0.77% Sep 11, 2023

Showing 1 to 17 CVEs · page 1