Total CVEs

113,593

Critical Severity

1,059

High Severity

3,317

Last 7 Days

949
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 121 - 140 of 9,998 CVEs
CVE-2026-27753 MEDIUM - 6.5

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unlimited login attempts against the management interface. Attackers can conduct online password guessing attacks without account lockout or rate limiting...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-27752 MEDIUM - 5.9

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse them to gain administra...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-27751 CRITICAL - 9.8

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to g...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-26862 HIGH - 8.3

CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src/modules/visualBuilder/pageBuilder.js (lines 56-60) uses the includes() method to verify the originUrl contains "da...

Vendor: npm
Product: clevertap-web-sdk
Published: Feb 27, 2026
Source: NVD
CVE-2026-26861 HIGH - 8.3

CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using the includes() method, which can be bypassed...

Vendor: npm
Product: clevertap-web-sdk
Published: Feb 27, 2026
Source: NVD

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.e...

Vendor: hexpm, erlang
Product: hex_core, hex, rebar3
Published: Feb 27, 2026
Source: NVD
CVE-2019-25497 HIGH - 8.2

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the currency parameter. Attackers can send GET requests to shopping_cart.php with malicious currency values using boolean-based SQL injection p...

Vendor: Oscommerce
Product: osCommerce
Published: Feb 27, 2026
Source: NVD
CVE-2019-25496 HIGH - 8.2

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the products_id parameter. Attackers can modify the products_id value in product_info.php requests and append boolean-based SQL injection paylo...

Vendor: Oscommerce
Product: osCommerce
Published: Feb 27, 2026
Source: NVD
CVE-2019-25495 HIGH - 8.2

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the reviews_id parameter. Attackers can send GET requests to product_reviews_write.php with malicious reviews_id values using boolean-based SQL...

Vendor: Oscommerce
Product: osCommerce
Published: Feb 27, 2026
Source: NVD
CVE-2019-25494 HIGH - 8.2

Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD
CVE-2019-25493 HIGH - 8.2

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'val' parameter. Attackers can send GET requests to the admin/getrecord.php endpoint with malicious 'val' values to extract ...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD
CVE-2019-25492 HIGH - 8.2

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pt' parameter. Attackers can send GET requests to the admin/getcmsdata.php endpoint with malicious 'pt' values to extract s...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD
CVE-2019-25491 HIGH - 8.2

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the catid parameter. Attackers can send GET requests to the admin/cms_getpagetitle.php endpoint with malicious catid values to extract sensitive dat...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD
CVE-2019-25490 HIGH - 8.2

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' parameter. Attackers can send GET requests to the admin/edit.php endpoint with time-based SQL injection payloads to extract sensit...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD
CVE-2019-25489 HIGH - 8.2

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id values to extract sen...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.

Published: Feb 27, 2026
Source: NVD
CVE-2026-25147 HIGH - 7.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $pid` and `$pid = ($_REQUEST['hidden...

Vendor: openemr
Product: openemr
Published: Feb 27, 2026
Source: NVD
CVE-2026-24488 MEDIUM - 6.5

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, an arbitrary file exfiltration vulnerability in the fax sending endpoint allows any authenticated user to read and transmit any file on the server (includin...

Vendor: openemr
Product: openemr
Published: Feb 27, 2026
Source: NVD
CVE-2025-69437 HIGH - 8.7

PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be...

Published: Feb 27, 2026
Source: NVD

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch...

Vendor: npm
Product: multer
Published: Feb 27, 2026
Source: NVD