Search

Found 17,403 results in 760ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-3795 critical 9.8 9.8 html-js 3mo ago A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a manipulation results in path tr…
CVE-2026-3794 critical 9.8 9.8 html-js 3mo ago A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper auth…
CVE-2026-3765 critical 9.8 9.8 angeljudesuarez 3mo ago A vulnerability was identified in itsourcecode University Management System 1.0. This affects an unknown function of the file /att_single_view.php. Such manipulation of the argument dt leads to sql i…
CVE-2026-3762 critical 9.8 9.8 lerouxyxchire 3mo ago A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The m…
CVE-2026-3760 critical 9.8 9.8 angeljudesuarez 3mo ago A vulnerability was detected in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /view_result.php. Performing a manipulation of the argument seme res…
CVE-2026-3759 critical 9.8 9.8 projectworlds 3mo ago A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm lead…
CVE-2026-3758 critical 9.8 9.8 projectworlds 3mo ago A weakness has been identified in projectworlds Online Art Gallery Shop 1.0. Affected by this issue is some unknown functionality of the file /admin/adminHome.php. This manipulation of the argument I…
CVE-2026-3757 critical 9.8 9.8 projectworlds 3mo ago A security flaw has been discovered in projectworlds Online Art Gallery Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /?pass=1. The manipulation of the argument fnm…
CVE-2026-3747 critical 9.8 9.8 angeljudesuarez 3mo ago A vulnerability was identified in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /add_result.php. Such manipulation of the argument su…
CVE-2026-3746 critical 9.8 9.8 oretnom23 3mo ago A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of th…
CVE-2026-3744 critical 9.8 9.8 carmelo 3mo ago A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql i…
CVE-2026-3740 critical 9.8 9.8 angeljudesuarez 3mo ago A weakness has been identified in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_search_student.php. This manipulation of the argument admin_search_…
CVE-2026-3736 critical 9.8 9.8 carmelo 3mo ago A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulati…
CVE-2026-3735 critical 9.8 9.8 carmelo 3mo ago A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulati…
CVE-2026-3730 critical 9.8 9.8 itsourcecode 3mo ago A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performi…
CVE-2026-3723 critical 9.8 9.8 carmelo 3mo ago A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno …
CVE-2026-3709 critical 9.8 9.8 carmelo 3mo ago A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /register.php. Executing a manipulation of the argument Username …
CVE-2026-3708 critical 9.8 9.8 carmelo 3mo ago A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the argu…
CVE-2026-3705 critical 9.8 9.8 carmelo 3mo ago A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno …
CVE-2026-3696 critical 9.8 9.8 3mo ago A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a ma…
CVE-2026-3668 low 3.1 3.1 3mo ago A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the component org.ethosmobile.webpwaemul. This manipulation causes improper access…
CVE-2026-26288 critical 9.8 9.8 everon 3mo ago WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can co…
CVE-2026-26051 critical 9.8 9.8 mvm 3mo ago WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can co…
CVE-2026-22552 critical 9.8 9.8 epower 3mo ago WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can co…
CVE-2026-28474 critical 9.8 9.8 openclaw 3mo ago Nextcloud Talk allowlist bypass via actor.name display name spoofing
CVE-2026-28395 critical 9.1 9.1 openclaw 3mo ago OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback
CVE-2025-11143 low 2.5 FIX debian debian sles 3mo ago org.eclipse.jetty:jetty-http has different parsing of invalid URIs
CVE-2025-29165 critical 9.8 9.8 3mo ago An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component
CVE-2026-2743 critical 9.8 9.8 seppmail 3mo ago Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 …
CVE-2026-22417 critical 9.8 9.8 3mo ago Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: from n/a through < 3.1.11.
CVE-2026-27820 critical 9.8 9.8 slesdebian debian ruby-lang 3mo ago Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
CVE-2026-27446 critical 9.8 9.8 apache 3mo ago Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions
CVE-2026-2590 critical 9.8 9.8 devolutions 3mo ago Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to p…
CVE-2026-3465 low 3.1 3.1 3mo ago A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the a…
CVE-2026-3449 low 3.3 3.3 sles 3mo ago @tootallnate/once vulnerable to Incorrect Control Flow Scoping
CVE-2026-3413 critical 9.8 9.8 angeljudesuarez 3mo ago A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql …
CVE-2026-3411 critical 9.8 9.8 angeljudesuarez 3mo ago A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /admin_single_student_update.php. The man…
CVE-2026-3410 critical 9.8 9.8 angeljudesuarez 3mo ago A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/check_studid.php. Executing a manipulation …
CVE-2026-3407 low 3.3 3.3 3mo ago A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes h…
CVE-2026-3406 critical 9.8 9.8 projectworlds 3mo ago A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The mani…
CVE-2026-3395 critical 9.8 9.8 max-3000 3mo ago A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX …
CVE-2026-28517 critical 9.8 10.0 EXP opendcim 3mo ago openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the databas…
CVE-2026-2880 critical 9.1 9.1 fastify 3mo ago @fastify/middie has Improper Path Normalization when Using Path-Scoped Middleware
CVE-2025-11252 critical 9.8 9.8 signumtte 3mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection. This issue affect…
CVE-2026-24352 critical 9.8 9.8 pluxml 3mo ago PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID…
CVE-2025-11251 critical 9.8 9.8 daynex 3mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows SQL Injection. This issue af…
CVE-2026-3289 critical 9.8 9.8 publiccms 3mo ago A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a …
CVE-2026-3287 critical 9.8 9.8 youlai 3mo ago A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuCon…
CVE-2026-20797 critical 9.8 9.8 3mo ago A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.
CVE-2026-3261 critical 9.8 9.8 itsourcecode 3mo ago A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argumen…
CVE-2026-3193 low 3.1 3.1 chia 3mo ago A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be perform…
CVE-2026-3187 critical 9.8 9.8 szadmin 3mo ago A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the component API Endpoi…
CVE-2026-21725 low 2.0 2.0 sles grafana 3mo ago A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to…
CVE-2026-3164 critical 9.8 9.8 clive_21 3mo ago A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle results in s…
CVE-2026-3153 critical 9.8 9.8 admerc 3mo ago A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injec…
CVE-2026-3152 critical 9.8 9.8 angeljudesuarez 3mo ago A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php. This manipulation of the argument teacher_id cau…
CVE-2026-3151 critical 9.8 9.8 angeljudesuarez 3mo ago A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The manipulation of the argument email results in sql…
CVE-2026-3148 critical 9.8 9.8 haben-cs9 3mo ago A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes …
CVE-2026-3135 critical 9.8 9.8 clive_21 3mo ago A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category cau…
CVE-2026-3134 critical 9.8 9.8 clive_21 3mo ago A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin/edit-category.php. The manipulation of the argum…
CVE-2026-3133 critical 9.8 9.8 admerc 3mo ago A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of the component Login. The manipulation of the argum…
CVE-2026-2786 critical 9.8 9.8 FIX rocky rheldebian debian mozilla 3mo ago Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-3069 critical 9.8 9.8 admerc 3mo ago A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to s…
CVE-2026-3068 critical 9.8 9.8 admerc 3mo ago A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to…
CVE-2026-3057 critical 9.8 9.8 a54552239 3mo ago A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Inter…
CVE-2026-3053 critical 9.8 9.8 dinky 3mo ago A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component Ope…
CVE-2026-3046 critical 9.8 9.8 emiloi 3mo ago A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The ma…
CVE-2026-3042 critical 9.8 9.8 admerc 3mo ago A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID result…
CVE-2026-3041 low 2.4 2.4 3mo ago A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the file src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html of th…
CVE-2026-3025 critical 9.8 9.8 shuoren 3mo ago A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.a…
CVE-2026-2983 critical 9.8 9.8 munyweki 3mo ago A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Impor…
CVE-2026-2974 low 2.5 2.5 aliasvault 3mo ago A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backup Handler. The mani…
CVE-2026-2968 low 3.7 3.7 FIX debian debian cesanta 3mo ago A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handle…
CVE-2026-2967 low 3.7 3.7 FIX debian debian cesanta 3mo ago A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulat…
CVE-2026-2966 low 3.7 3.7 FIX debian debian cesanta 3mo ago A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipu…
CVE-2026-2965 low 2.4 2.4 3mo ago A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown function of the file /admin/SysModule/edit.html of the component System Extensi…
CVE-2026-2964 critical 9.8 9.8 higuma 3mo ago A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipul…
CVE-2026-2954 critical 9.8 9.8 ujcms 3mo ago A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a ma…
CVE-2026-2953 critical 9.1 9.1 ujcms 3mo ago A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete of the component Template Handler. Such manipulatio…
CVE-2026-2952 critical 9.8 9.8 vaelsys 3mo ago A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request Handler. This manipulation of the argument xajaxar…
CVE-2026-2944 critical 9.8 9.8 tosei-corporation 3mo ago A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file /cgi-bin/monitor.php of the component HTTP POST Request Handl…
CVE-2026-2912 critical 9.8 9.8 fabian 3mo ago A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation…
CVE-2026-2903 low 3.3 3.3 FIX slesdebian debian 3mo ago A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack ca…
CVE-2026-2889 low 3.3 3.3 debian debian 3mo ago A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only…
CVE-2026-2867 critical 9.8 9.8 admerc 4mo ago A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql …
CVE-2026-2865 critical 9.8 9.8 adonesevangelista 4mo ago A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler.…
CVE-2026-2848 critical 9.8 9.8 oretnom23 4mo ago A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component R…
CVE-2026-26725 critical 9.8 9.8 edubusinesssolutions 4mo ago An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID parameter.
CVE-2026-22384 critical 9.8 9.8 4mo ago Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7.
CVE-2025-10970 critical 9.8 9.8 4mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection. This issue affects Talentics: through …
CVE-2026-2825 low 3.5 3.5 4mo ago A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file tools/fix.py of the component Article Module. The manipulation leads to cross si…
CVE-2025-9953 critical 9.8 9.8 4mo ago Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Data…
CVE-2025-8350 critical 9.8 9.8 4mo ago Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splittin…
CVE-2026-2709 low 3.5 3.5 4mo ago A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-master/src/server/app.js of the component Callback Handler. Executing a manipulatio…
CVE-2026-2702 low 3.1 3.1 4mo ago A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the component WPA2 PSK. Performing a manipulation results in hard-coded credentials.…
CVE-2026-2691 critical 9.8 9.8 admerc 4mo ago A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argum…
CVE-2026-2690 critical 9.8 9.8 admerc 4mo ago A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. Th…
CVE-2026-2689 critical 9.8 9.8 admerc 4mo ago A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql inj…
CVE-2026-2684 critical 9.8 9.8 unigroup 4mo ago A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html.…
CVE-2026-2682 critical 9.8 9.8 unigroup 4mo ago A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such…