Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,960
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,481 - 2,500 of 3,450 CVEs
CVE-2026-26720 CRITICAL - 9.8

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

Vendor: twenty
Product: twenty
Published: Mar 02, 2026
Source: NVD
CVE-2026-26701 CRITICAL - 9.8

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php.

Vendor: jon-remus-sevellejo
Product: personnel_property_equipment_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-24112 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addWewifiWhiteUser` function and processed by `sscanf` without size validation, it could lead to a buffer overflow vulnerability...

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-24110 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule, " %d\t%[^\t]\t%[^\n\r\t]", &dhcpsIndex, dhcpsIP, dhcpsMac);`, the lack of size valida...

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-24101 CRITICAL - 9.8

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.

Vendor: tenda
Product: ac15_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2025-52998 CRITICAL - 9.8

Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and thus modify the logic of the web application'...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 02, 2026
Source: NVD
CVE-2025-50199 CRITICAL - 9.1

Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30.

Vendor: chamilo
Product: chamilo-lms
Published: Mar 02, 2026
Source: NVD
CVE-2026-26703 CRITICAL - 9.8

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php.

Vendor: jon-remus-sevellejo
Product: personnel_property_equipment_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26702 CRITICAL - 9.8

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php.

Vendor: jon-remus-sevellejo
Product: personnel_property_equipment_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26696 CRITICAL - 9.8

code-projects Simple Student Alumni System code-projects v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.

Vendor: carmelo
Product: simple_student_alumni_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26695 CRITICAL - 9.8

code-projects Simple Student Alumni System code-projects v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.

Vendor: carmelo
Product: simple_student_alumni_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26694 CRITICAL - 9.8

code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.

Vendor: carmelo
Product: simple_student_alumni_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-24115 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstruleQos` may lead to buffer overflow.

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-24114 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`.

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-24113 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a buffer overflow vulnerab...

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-24111 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addAuthUser` function and processed by `sscanf` without size validation, it could lead to buffer overflow.

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-24109 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this value is used in `sprintf` without validating variable sizes, it could lead to a buffer overflow vulnerability.

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-24108 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a buffer overflow vulnerab...

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-24107 CRITICAL - 9.8

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities.

Vendor: tenda
Product: w20e_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2025-50192 CRITICAL - 9.8

Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.

Vendor: chamilo
Product: chamilo-lms
Published: Mar 02, 2026
Source: NVD