Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,161 - 3,180 of 34,447 CVEs

A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of the argument name/address/fname results in cross site scripting. It is possible to launch ...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11533 MEDIUM - 5.4

A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deletion Endpoint. The manipulation of the argument del leads to i...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11532 MEDIUM - 6.3

A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record Handler. Executing a manipulation can lead to improper access controls. The attack may be performe...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11531 HIGH - 7.3

A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the component Administrator Login Endpoint. Performing a manipulation of the argument a_usr/a_pwd results in...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11530 HIGH - 7.3

A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely. T...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-49975 HIGH - 7.5

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by interpolating the caller-supplied name, ...

Vendor: wojtekmach
Product: req
Published: Jun 08, 2026
Source: NVD

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to exhaust memory in a Req client via decompression-bomb response bodies. Req's default response pipeline includes Req.Steps.decode_body/1 and Req.Steps.deco...

Vendor: wojtekmach
Product: req
Published: Jun 08, 2026
Source: NVD
CVE-2026-48913 HIGH - 7.3

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.

Vendor: thorsten
Product: phpMyFAQ
Published: Jun 08, 2026
Source: NVD
CVE-2026-46657 HIGH - 7.1

Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a user account, the application fails to invalidate or clear the ...

Vendor: bludit
Product: bludit
Published: Jun 08, 2026
Source: NVD
CVE-2026-46656 HIGH - 8.8

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthor...

Vendor: bludit
Product: bludit
Published: Jun 08, 2026
Source: NVD
CVE-2026-46443 MEDIUM - 6.5

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter parameter, the encryptedData field is not stripped from the response. The code properly omits encryptedData when no filter is...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD
CVE-2026-46442 CRITICAL - 9.9

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_A...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD
CVE-2026-46441 CRITICAL - 9.6

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceI...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD
CVE-2026-46440 HIGH - 7.5

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD
CVE-2026-46275 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer Dereference (NPD) conditions were observed in the lifecycle management of hci_uart. The pr...

Vendor: Linux
Product: Linux
Published: Jun 08, 2026
Source: NVD
CVE-2026-46274 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is hashed in io_wq_remove_pending() io_wq_remove_pending() needs to fix up wq->hash_tail[] if the cancelled work was the tail of its hash bucket. When doing this, it checks whether the precedin...

Vendor: Linux
Product: Linux
Published: Jun 08, 2026
Source: NVD
CVE-2026-44631 CRITICAL - 9.8

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-44186 HIGH - 7.3

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes ...

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD