Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,334
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,481 - 2,500 of 33,671 CVEs
CVE-2026-11492 MEDIUM - 4.3

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to th...

Vendor: D-Link
Product: DIR-823G
Published: Jun 08, 2026
Source: NVD

A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Trigger...

Vendor: CodeAstro
Product: Human Resource Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11490 HIGH - 7.3

A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed...

Vendor: code-projects
Product: Online Music Site
Published: Jun 08, 2026
Source: NVD
CVE-2026-11489 HIGH - 7.3

A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and c...

Vendor: code-projects
Product: Online Music Site
Published: Jun 08, 2026
Source: NVD
CVE-2026-11488 HIGH - 7.3

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely...

Vendor: code-projects
Product: Simple Flight Ticket Booking System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11487 MEDIUM - 5.3

A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The exp...

Product: Neovim
Published: Jun 08, 2026
Source: NVD
CVE-2026-11486 HIGH - 7.3

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /archive1.php. Performing a manipulation of the argument sy results in sql injection. Remote exploitation of the attack is possible. The exploi...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11485 HIGH - 7.3

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive2.php. Such manipulation of the argument sy leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11484 HIGH - 7.3

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /archive3.php. This manipulation of the argument sy causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and c...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11483 HIGH - 7.3

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /archive4.php. The manipulation of the argument sy results in sql injection. The attack can be launched remotely. The exploit has been released to the public and ...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11482 HIGH - 7.3

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /archive5.php. The manipulation of the argument sy leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The...

Vendor: yoanbernabeu
Product: grepai
Published: Jun 08, 2026
Source: NVD
CVE-2026-11480 MEDIUM - 6.3

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. Impacted is an unknown function of the file beike/Admin/Routes/admin.php of the component Admin Design Builder Endpoint. Performing a manipulation of the argument settings.value results in sql injection. It i...

Vendor: Chengdu Everbrite Network Technology
Product: BeikeShop
Published: Jun 08, 2026
Source: NVD
CVE-2026-11479 MEDIUM - 4.2

A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manipulation leads to use of weak hash. The attack may be performed from remote. Attacks of this nature are highly complex. Th...

Vendor: yoanbernabeu
Product: grepai
Published: Jun 08, 2026
Source: NVD

A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern Handler. This manipulation causes inefficient regular expression complexity. The attack is restricted to local execu...

Vendor: kokke
Product: tiny-regex-c
Published: Jun 08, 2026
Source: NVD
CVE-2026-11477 MEDIUM - 4.3

A vulnerability was detected in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in open ...

Vendor: hs-web
Product: hsweb-framework
Published: Jun 08, 2026
Source: NVD
CVE-2026-11476 MEDIUM - 6.3

A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this issue is the function edit-admin of the file controllers/AdminController.php of the component Profile Update Endpoint. The manipulation of the argument is...

Vendor: Kushan2k
Product: student-management-system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11475 MEDIUM - 6.3

A weakness has been identified in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this vulnerability is the function getStatus of the file controllers/GradeController.php of the component Certificate Verification Endpoint. Executing a manipulation of th...

Vendor: Kushan2k
Product: student-management-system
Published: Jun 08, 2026
Source: NVD
CVE-2024-58349 CRITICAL - 9.8

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute th...

Vendor: WP Travel Kit
Product: Travelscape
Published: Jun 08, 2026
Source: NVD
CVE-2024-58348 CRITICAL - 9.8

WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to execute arbitrary co...

Vendor: background-image-cropper
Product: Background Image Cropper
Published: Jun 08, 2026
Source: NVD