CVEs from 2026
Total
14,726
critical
critical 1,327
high
high 4,986
medium
medium 4,775
low
low 502
% Critical
9.0%
% with KEV
0.4%
% with exploit
0.7%
Top vendors
Top products
- chrome 723
- firepower_threat_defense_software 310
- gcp 299
- firepower_threat_defense 298
- openclaw 172
- commerce 104
- netweaver_application_server_abap 102
- commerce_b2b 89
Top packages
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-6586 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoi… | |||
| CVE-2026-6576 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat Bot Int… | |||
| CVE-2026-6573 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of t… | |||
| CVE-2026-6571 | medium | 6.3 | 6.3 | 2mo ago | A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipul… | |||
| CVE-2026-6497 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the compon… | |||
| CVE-2026-6489 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Backg… | |||
| CVE-2026-6488 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affects unknown code of the file admin/editcourse.php of the component GET Request P… | |||
| CVE-2026-6215 | medium | 6.3 | 6.3 | 2mo ago | A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.ts of the component REST/GraphQL. This manipulatio… | |||
| CVE-2026-6202 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection… | |||
| CVE-2026-6191 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead… | |||
| CVE-2026-6190 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /employees.php. Performing a manipulation of the argument Name re… | |||
| CVE-2026-6143 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. … | |||
| CVE-2026-6141 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/Tools/parse_url.ts. Executing a manipulation can lea… | |||
| CVE-2026-6125 | medium | 6.3 | 6.3 | 2mo ago | Warm-Flow has a SpEL Expression Injection in SpelHelper.parseExpression | |||
| CVE-2026-6119 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation leads to server-side request fo… | |||
| CVE-2026-6118 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. This manipulat… | |||
| CVE-2026-6117 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload End… | |||
| CVE-2026-6108 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_mcp_node.py of the component Mod… | |||
| CVE-2026-40354 | medium | 6.3 | 6.3 | 2mo ago | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash. | |||
| CVE-2026-6033 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fna… | |||
| CVE-2026-6030 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /del1.php. This manipulation of the argument toolname causes sql inje… | |||
| CVE-2026-6010 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/takeassessment2.php?exid=14. Perfo… | |||
| CVE-2026-6007 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injectio… | |||
| CVE-2026-6006 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown function of the file /edit_hpatient.php. The manipulation of the argument ID l… | |||
| CVE-2026-6005 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a manipulation of the argument he… | |||
| CVE-2026-5999 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulation leads to improper authorization. The attack can… | |||
| CVE-2026-5823 | medium | 6.3 | 6.3 | 2mo ago | A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_report.php. This manipulation of the… | |||
| CVE-2026-5803 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API… | |||
| CVE-2026-5719 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql… | |||
| CVE-2026-5681 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the… | |||
| CVE-2026-5675 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the a… | |||
| CVE-2026-5670 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move_uploaded_file of the file /AssignmentSection/subm… | |||
| CVE-2026-5660 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This… | |||
| CVE-2026-5659 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/datrie.pyx of the component trie File Handler. The … | |||
| CVE-2026-5649 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in code-projects Online Application System for Admission 1.0. This issue affects some unknown processing of the file /enrollment/admsnform.php of the component Endpoint… | |||
| CVE-2026-5641 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-image1.php of the component Parameter Handler. The ma… | |||
| CVE-2026-5640 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. T… | |||
| CVE-2026-5639 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulati… | |||
| CVE-2026-5636 | medium | 6.3 | 6.3 | 2mo ago | A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the… | |||
| CVE-2026-5635 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Para… | |||
| CVE-2026-5623 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to … | |||
| CVE-2026-5620 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in itsourcecode Construction Management System 1.0. Affected is an unknown function of the file /borrowed_equip_report.php of the component Parameter Handler. The manip… | |||
| CVE-2026-5607 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src/handlers.ts of the component URL Parameter Handle… | |||
| CVE-2026-5597 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in griptape-ai griptape 0.19.4. This affects an unknown part of the file griptape\tools\computer\tool.py of the component ComputerTool. Executing a manipulation of the argument … | |||
| CVE-2026-5596 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was detected in griptape-ai griptape 0.19.4. Affected by this issue is some unknown functionality of the file griptape/tools/sql/tool.py of the component SqlTool. Performing a manipul… | |||
| CVE-2026-5595 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save_content_to_file/save_memory_ar… | |||
| CVE-2026-5594 | medium | 6.3 | 6.3 | 2mo ago | A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.py. This manipulation of the argument result causes… | |||
| CVE-2026-5587 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4. This affects the function _execute_sql of the file core/agents.py of the component Refiner Agent… | |||
| CVE-2026-5586 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in zhongyu09 openchatbi up to 0.2.1. The impacted element is an unknown function of the component Multi-stage Text2SQL Workflow. Executing a manipulation of the argumen… | |||
| CVE-2026-5583 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /my-profile.php of the component Parameter Handler. The manipulat… | |||
| CVE-2026-5580 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/addvideos.php of the component Parameter Handler. The manipulation of th… | |||
| CVE-2026-5579 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in CodeAstro Online Classroom 1.0. This issue affects some unknown processing of the file /OnlineClassroom/updatedetailsfromfaculty.php?myfid=108 of the component Param… | |||
| CVE-2026-5578 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /OnlineClassroom/addassessment.php of the component Parameter Handler. Performing a ma… | |||
| CVE-2026-5559 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the file sandbox.py of the component AST Validation. Such manipu… | |||
| CVE-2026-5563 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in AutohomeCorp frostmourne up to 1.0. Affected is the function httpTest of the file /api/monitor-api/alarm/previewData of the component Alarm Preview. The manipul… | |||
| CVE-2026-5561 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in Campcodes Complete POS Management and Inventory System up to 4.0.6. This affects an unknown function of the file app/Http/Controllers/SettingsController.php of the c… | |||
| CVE-2026-5560 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /payment-method.php of the component Parameter Handler. Performing … | |||
| CVE-2026-5558 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manip… | |||
| CVE-2026-5557 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file packages/mom/src/slack.ts of the component pi-mom Slack Bot. The manipulation res… | |||
| CVE-2026-5556 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function discoverAndLoadExtensions of the file packages/coding-agent/src/core/extensions/lo… | |||
| CVE-2026-5553 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler… | |||
| CVE-2026-5552 | medium | 6.3 | 6.3 | 2mo ago | A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This mani… | |||
| CVE-2026-5546 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrest… | |||
| CVE-2026-5543 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected element is an unknown function of the file /admin/yesterday-reg-users.php. The mani… | |||
| CVE-2026-5537 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the … | |||
| CVE-2026-5532 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the co… | |||
| CVE-2026-5528 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command inject… | |||
| CVE-2026-5472 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php… | |||
| CVE-2026-5470 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractC… | |||
| CVE-2026-5344 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt_uploadImage of the file rpc/TXP_RPCServer.php of the component XML-RPC Handler… | |||
| CVE-2026-5328 | medium | 6.3 | 6.3 | 2mo ago | A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listItem of the file src/main/java/com/suisung/shopsuite… | |||
| CVE-2026-5327 | medium | 6.3 | 6.3 | 2mo ago | fast-filesystem-mcp is vulnerable to command injection through handleGetDiskUsage function | |||
| CVE-2026-1879 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a man… | |||
| CVE-2026-5259 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/contro… | |||
| CVE-2026-5273 | medium | 6.3 | 6.3 | 2mo ago | Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |||
| CVE-2026-5251 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument is… | |||
| CVE-2026-5248 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such man… | |||
| CVE-2026-5206 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argumen… | |||
| CVE-2026-5205 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such man… | |||
| CVE-2026-5197 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql … | |||
| CVE-2026-5196 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The manipulation of the argument ID leads to sql injecti… | |||
| CVE-2026-5181 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_ca… | |||
| CVE-2026-5126 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to … | |||
| CVE-2026-5011 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the file /webhook of the component JSON Parser. Performing a manipulation of the argum… | |||
| CVE-2026-4999 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue affects the function uploadFile of the file /server/utils/upload.js of the compon… | |||
| CVE-2026-4970 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argu… | |||
| CVE-2026-4966 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /admin/mod_room/index.php?view=edit. Executing a manipulation of the argument ID c… | |||
| CVE-2026-4980 | medium | 6.3 | 6.3 | 2mo ago | A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:inclu… | |||
| CVE-2026-4954 | medium | 6.3 | 6.3 | 2mo ago | A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List End… | |||
| CVE-2026-4907 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function sitemap.fetch of the file /sitemap of the component En… | |||
| CVE-2026-4876 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulatio… | |||
| CVE-2026-4836 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the file /my_account/delete.php. Performing a manipulation of the argument cos_id r… | |||
| CVE-2026-4783 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/add-single-student-results.php of the component Parameter … | |||
| CVE-2026-4614 | medium | 6.3 | 6.3 | 2mo ago | A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This… | |||
| CVE-2026-4597 | medium | 6.3 | 6.3 | 2mo ago | A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. Impacted is the function selectAll of the file src/main/java/com/genersoft/iot/vmp/streamProxy/dao/provider/StreamProxyPr… | |||
| CVE-2026-4593 | medium | 6.3 | 6.3 | 2mo ago | A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the co… | |||
| CVE-2026-4589 | medium | 6.3 | 6.3 | 3mo ago | A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the componen… | |||
| CVE-2026-4586 | medium | 6.3 | 6.3 | 3mo ago | A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/server/web… | |||
| CVE-2026-4574 | medium | 6.3 | 6.3 | 3mo ago | A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Update Handler. The manipulation of the argument fir… | |||
| CVE-2026-4573 | medium | 6.3 | 6.3 | 3mo ago | A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_handlers/delete_post.php of the component HTTP GET P… |