Total CVEs

113,593

Critical Severity

1,059

High Severity

3,317

Last 7 Days

955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 9,998 CVEs
CVE-2026-3422 CRITICAL - 9.8

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

Published: Mar 02, 2026
Source: NVD
CVE-2026-3413 HIGH - 7.3

A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may ...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3000 CRITICAL - 9.8

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.

Published: Mar 02, 2026
Source: NVD
CVE-2026-2999 CRITICAL - 9.8

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

Published: Mar 02, 2026
Source: NVD
CVE-2025-15597 MEDIUM - 6.3

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disc...

Vendor: Dataease
Product: SQLBot
Published: Mar 02, 2026
Source: NVD
CVE-2026-3412 MEDIUM - 4.3

A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file /att_single_view.php. The manipulation of the argument dt results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.

Published: Mar 02, 2026
Source: NVD
CVE-2026-3411 HIGH - 7.3

A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /admin_single_student_update.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. T...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3410 HIGH - 7.3

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/check_studid.php. Executing a manipulation of the argument student_id can lead to sql injection. The attack may be launched remotely. The exploi...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3409 HIGH - 7.3

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import Endpoint. Performing a manipulation as part of File results in code injection. The attac...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3408 MEDIUM - 4.3

A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit is publicly available an...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3407 LOW - 3.3

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has bee...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3406 HIGH - 7.3

A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotely...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3405 LOW - 3.1

A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitabi...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3404 MEDIUM - 5.0

A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The attack may be performed from remote. Attacks of this...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3403 LOW - 2.4

A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The explo...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3402 LOW - 2.4

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The explo...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3401 LOW - 3.1

A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitabi...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3400 HIGH - 8.8

A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionality of the file /goform/TextEditingConversion. The manipulation of the argument wpapsk_crypto2_4g results in stack-based buffer overflow. The attack may be launched remotely. The exp...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3399 HIGH - 8.8

A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. The manipulation of the argument dips leads to buffer overflow. The attack may be initiated remotely. The exploit is public...

Published: Mar 01, 2026
Source: NVD
CVE-2026-3398 HIGH - 8.8

A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead to buffer overflow. The attack can be launched remotely. The exploit has been pub...

Published: Mar 01, 2026
Source: NVD