Search

Found 33,988 results in 1274ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-2212 critical 9.8 9.8 fabian 4mo ago A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Administrator/PHP/AdminEditCategory.php. The manipulatio…
CVE-2026-2211 critical 9.8 9.8 fabian 4mo ago A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCategory.php. Executing a manipulation of the argument…
CVE-2026-2199 critical 9.8 9.8 fabian 4mo ago A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. P…
CVE-2026-2198 critical 9.8 9.8 fabian 4mo ago A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipu…
CVE-2026-2197 critical 9.8 9.8 fabian 4mo ago A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of…
CVE-2026-2196 critical 9.8 9.8 fabian 4mo ago A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulati…
CVE-2026-2195 critical 9.8 9.8 fabian 4mo ago A vulnerability has been found in code-projects Online Reviewer System 1.0. This vulnerability affects unknown code of the file /system/system/admins/assessments/pretest/questions-view.php. The manip…
CVE-2026-2190 critical 9.8 9.8 itsourcecode 4mo ago A security flaw has been discovered in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/user/controller.php. The manipulation of the argument ID resul…
CVE-2026-2189 critical 9.8 9.8 itsourcecode 4mo ago A vulnerability was identified in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/report/index.php. The manipulation of the argument ay leads to sql …
CVE-2026-2172 critical 9.8 9.8 fabian 4mo ago A vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the compone…
CVE-2026-2171 critical 9.8 9.8 fabian 4mo ago A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argu…
CVE-2026-2166 critical 9.8 9.8 fabian 4mo ago A security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulati…
CVE-2026-2165 critical 9.8 9.8 detronetdip 4mo ago A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Exe…
CVE-2026-2164 critical 9.8 9.8 detronetdip 4mo ago A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/profile/addadhar.php. Performing a manipulation of t…
CVE-2026-2161 critical 9.8 9.8 clive_21 4mo ago A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argumen…
CVE-2026-2136 critical 9.8 9.8 projectworlds 4mo ago A flaw has been found in projectworlds Online Food Ordering System 1.0. This affects an unknown function of the file /view-ticket.php. Executing a manipulation of the argument ID can lead to sql inje…
CVE-2026-2133 critical 9.8 9.8 fabian 4mo ago A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCategory.php. This manipulation of the argument txtima…
CVE-2026-2132 critical 9.8 9.8 fabian 4mo ago A security flaw has been discovered in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Administrator/PHP/AdminUpdateCategory.php. The manipulation of the …
CVE-2026-2122 critical 9.8 9.8 xiaopi 4mo ago A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.php of the component WAF Firewall. The manipulation of the argument ID results i…
CVE-2026-2117 critical 9.8 9.8 angeljudesuarez 4mo ago A vulnerability was found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/edit_activity.php. Performing a manipulation of the argument ac…
CVE-2026-2116 critical 9.8 9.8 angeljudesuarez 4mo ago A vulnerability has been found in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/edit_expenses.php. Such manipulation of the argument expenses_id leads…
CVE-2026-2115 critical 9.8 9.8 angeljudesuarez 4mo ago A flaw has been found in itsourcecode Society Management System 1.0. This issue affects some unknown processing of the file /admin/delete_expenses.php. This manipulation of the argument expenses_id c…
CVE-2026-2114 critical 9.8 9.8 angeljudesuarez 4mo ago A vulnerability was detected in itsourcecode Society Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_admin.php. The manipulation of the argument admin_id result…
CVE-2026-2113 critical 9.8 9.8 tpadmin_project 4mo ago A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component…
CVE-2026-2090 critical 9.8 9.8 janobe 4mo ago A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown processing of the file /admin/message/search.php. Executing a manipulation of the argu…
CVE-2026-2089 critical 9.8 9.8 janobe 4mo ago A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of the file /admin/subject/controller.php. Performing a manipulation of the argumen…
CVE-2026-2088 critical 9.8 9.8 phpgurukul 4mo ago A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid le…
CVE-2026-2087 critical 9.8 9.8 janobe 4mo ago A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email…
CVE-2026-2083 critical 9.8 9.8 code-projects 4mo ago A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in…
CVE-2026-2073 critical 9.8 9.8 itsourcecode 4mo ago A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. Executing a manipulation of the argument ID can lea…
CVE-2026-1709 critical 9.5 FIX rhel sles rocky 4mo ago Keylime Missing Authentication for Critical Function and Improper Authentication
CVE-2026-2060 critical 9.8 9.8 fabian 4mo ago A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Per…
CVE-2026-2059 critical 9.8 9.8 bontrofftech 4mo ago A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to…
CVE-2026-2058 critical 9.8 9.8 vishalmathur 4mo ago A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Pos…
CVE-2026-2057 critical 9.8 9.8 bontrofftech 4mo ago A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in s…
CVE-2026-1337 unknown 4mo ago Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log
CVE-2026-2018 critical 9.8 9.8 itsourcecode 4mo ago A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID causes sql injecti…
CVE-2026-2014 critical 9.8 9.8 itsourcecode 4mo ago A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/index.php. Performing a manipulation of the argument …
CVE-2026-2013 critical 9.8 9.8 itsourcecode 4mo ago A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql i…
CVE-2026-2012 critical 9.8 9.8 itsourcecode 4mo ago A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /ramonsys/facultyloading/index.php. This manipulation of the argu…
CVE-2026-2011 critical 9.8 9.8 itsourcecode 4mo ago A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /ramonsys/enrollment/controller.php. The manipulation of the argument …
CVE-2026-25732 unknown 1.0 EXP 4mo ago NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
CVE-2025-68458 unknown FIX debian debian 4mo ago Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts out…
CVE-2025-68157 unknown FIX debian debian 4mo ago Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, bu…
CVE-2025-58190 unknown FIX debian debian sles 4mo ago The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML …
CVE-2026-24423 unknown 1.5 KEV 4mo ago SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a mal…
CVE-2025-5329 critical 9.8 9.8 4mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection. This issue affects Delta Co…
CVE-2026-1622 unknown 4mo ago Neo4j Enterprise and Community vulnerable to a potential information disclosure
CVE-2026-1813 critical 9.8 9.8 adlered 4mo ago A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the component FreeMarker Tem…
CVE-2026-1812 critical 9.8 9.8 adlered 4mo ago A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component F…
CVE-2026-1341 unknown 4mo ago Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.
CVE-2026-23795 unknown 4mo ago Apache Syncope: Console XXE on Keymaster parameters
CVE-2026-23794 unknown 4mo ago Apache Syncope: Reflected XSS on Enduser Login
CVE-2026-25526 unknown 4mo ago JinJava Bypass through ForTag leads to Arbitrary Java Execution
CVE-2026-1312 unknown FIX slesdebian debian 4mo ago Django has an SQL Injection issue
CVE-2026-1287 unknown FIX slesdebian debian 4mo ago Django has an SQL Injection issue
CVE-2026-1285 unknown FIX slesdebian debian 4mo ago Django has Inefficient Algorithmic Complexity
CVE-2026-1207 unknown FIX slesdebian debian 4mo ago Django has an SQL Injection issue
CVE-2025-14550 unknown FIX slesdebian debian 4mo ago Django has Inefficient Algorithmic Complexity
CVE-2025-13473 unknown FIX slesdebian debian 4mo ago Django has Observable Timing Discrepancy
CVE-2025-5319 critical 9.8 9.8 4mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Man…
CVE-2025-64328 unknown 2.5 KEVEXP 4mo ago Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> c…
CVE-2025-40551 unknown 2.5 KEVEXP 4mo ago SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This c…
CVE-2019-19006 unknown 1.5 KEV 4mo ago Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.
CVE-2026-24051 unknown FIX debian debian google 4mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The re…
CVE-2026-1770 unknown 4mo ago Crafter CMS has Improper Control of Dynamically-Managed Code Resources
CVE-2026-1703 unknown FIX slesdebian debian 4mo ago When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation dir…
CVE-2024-5986 unknown 4mo ago H2O has an External Control of File Name or Path vulnerability
CVE-2026-1518 unknown 4mo ago Keycloak Server-Side Request Forgery (SSRF) vulnerability
CVE-2025-13881 unknown 4mo ago Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
CVE-2026-1740 critical 9.8 9.8 4mo ago A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup Interface. The manipu…
CVE-2026-23038 unknown FIX slesdebian debian 4mo ago In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versi…
CVE-2026-23037 unknown FIX slesdebian debian 4mo ago In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow partial RX URB allocation to succeed When es58x_alloc_rx_urbs() fails to allocate the requested number of …
CVE-2026-23033 unknown FIX slesdebian debian 4mo ago In the Linux kernel, the following vulnerability has been resolved: dmaengine: omap-dma: fix dma_pool resource leak in error paths The dma_pool created by dma_pool_create() is not destroyed when dm…
CVE-2026-23032 unknown FIX slesdebian debian 4mo ago In the Linux kernel, the following vulnerability has been resolved: null_blk: fix kmemleak by releasing references to fault configfs items When CONFIG_BLK_DEV_NULL_BLK_FAULT_INJECTION is enabled, t…
CVE-2026-23031 unknown FIX slesdebian debian 4mo ago In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak In gs_can_open(), the URBs for USB-in transfers are allocated, a…
CVE-2026-23030 unknown FIX slesdebian debian 4mo ago In the Linux kernel, the following vulnerability has been resolved: phy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe() The for_each_available_child_of_node() calls of_node_…
CVE-2025-69662 unknown FIX debian debian 4mo ago geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure
CVE-2026-1701 critical 9.8 9.8 itsourcecode 4mo ago A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argumen…
CVE-2026-1688 critical 9.8 9.8 clive_21 4mo ago A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /admin/index.php. The manipulation of the argument …
CVE-2024-4027 unknown debian debian 4mo ago Undertow Servlets Vulnerable to Remote DoS via OutOfMemoryError when Passed Large Parameter Names
CVE-2026-1595 critical 9.8 9.8 angeljudesuarez 4mo ago A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. The manipulation of the argument student_id results…
CVE-2026-1594 critical 9.8 9.8 angeljudesuarez 4mo ago A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_expenses.php. The manipulation of…
CVE-2026-1593 critical 9.8 9.8 angeljudesuarez 4mo ago A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit_expenses_query.php. Executing a manipu…
CVE-2026-1590 critical 9.8 9.8 angeljudesuarez 4mo ago A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/faculty/index.php. Such manipulation of the argument ID leads to sq…
CVE-2026-1589 critical 9.8 9.8 angeljudesuarez 4mo ago A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php. This manipulation of the argument txtsearch caus…
CVE-2020-37002 critical 9.8 9.8 4mo ago Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execute arbitrary commands after successful login. Attackers can leverage the /api/t…
CVE-2026-1552 critical 9.8 9.8 sem-cms 4mo ago A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The a…
CVE-2026-1281 unknown 2.5 KEVEXP 4mo ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-1547 critical 9.8 9.8 4mo ago A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in comma…
CVE-2026-1546 critical 9.8 9.8 jishenghua 4mo ago A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshERP-boot/depotItem/importItemExcel of the component …
CVE-2026-1545 critical 9.8 9.8 angeljudesuarez 4mo ago A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function of the file /course/index.php. Executing a manipulation of the argument ID can…
CVE-2026-24739 unknown FIX debian debian 4mo ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not cor…
CVE-2026-1535 critical 9.8 9.8 fabian 4mo ago A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Administrator/PHP/AdminReply.php. Such manipulation of the argument ID…
CVE-2026-1534 critical 9.8 9.8 fabian 4mo ago A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Administrator/PHP/AdminEditUser.php. This manipulation of the argument ID causes s…
CVE-2026-1533 critical 9.8 9.8 fabian 4mo ago A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminAddCategory.php. The manipulation results i…
CVE-2025-61730 unknown FIX debian debian sles 4mo ago During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages …
CVE-2025-68119 unknown FIX debian debian sles google 4mo ago Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom d…
CVE-2026-24765 unknown FIX debian debian 4mo ago PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in…
CVE-2026-24858 critical 9.8 10.0 KEV fortinet 4mo ago Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a register…