Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,976
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,221 - 3,240 of 34,447 CVEs
CVE-2026-11515 MEDIUM - 5.3

A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input passw...

Vendor: SourceCodester
Product: Barangay Resident Profiling and Information Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11514 MEDIUM - 6.3

A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11513 MEDIUM - 6.3

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11512 MEDIUM - 4.3

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclos...

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD

A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a manipulation of the argument style can lead to HTML injection. It is possible to launch the attack remo...

Vendor: Bolt
Product: CMS
Published: Jun 08, 2026
Source: NVD
CVE-2026-50752 HIGH - 7.4

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow ...

Vendor: checkpoint
Product: Quantum Security Gateway, Spark Firewalls
Published: Jun 08, 2026
Source: NVD
CVE-2026-50751 CRITICAL - 9.3

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Vendor: checkpoint
Product: Quantum Security Gateway, Spark Firewalls
Published: Jun 08, 2026
Source: NVD

## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560โ€“574`). Any web content loaded inside the InAppBrowser can fire any pending Cor...

Vendor: Apache Software Foundation
Product: Cordova Plugin InAppBrowser
Published: Jun 08, 2026
Source: NVD
CVE-2026-3011 MEDIUM - 6.4

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' met...

Published: Jun 08, 2026
Source: NVD
CVE-2026-11569 MEDIUM - 5.4

A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored cross-site scripting when ...

Vendor: Red Hat
Product: Red Hat Quay 3
Published: Jun 08, 2026
Source: NVD
CVE-2026-11510 MEDIUM - 6.3

A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection. It is possible to initiate the attack remotely. The exploit has been released...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11509 MEDIUM - 6.3

A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote.

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11508 MEDIUM - 6.3

A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The ex...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11507 MEDIUM - 6.3

A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/delete_leave_type.php. The manipulation of the argument leave_type results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11506 MEDIUM - 6.3

A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to t...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11505 MEDIUM - 5.0

A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a ...

Vendor: GL.iNet
Product: A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000
Published: Jun 08, 2026
Source: NVD
CVE-2026-11504 HIGH - 8.8

A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration Endpoint. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer ove...

Vendor: Tenda
Product: CX12L
Published: Jun 08, 2026
Source: NVD

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outsi...

Published: Jun 08, 2026
Source: NVD
CVE-2026-11503 HIGH - 8.8

A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set of the component Wi-Fi Configuration Endpoint. Such manipulation of the argument ssid leads to stack-based buffer overflow....

Vendor: Tenda
Product: CX12L
Published: Jun 08, 2026
Source: NVD

A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login. This manipulation of the...

Product: JeecgBoot
Published: Jun 08, 2026
Source: NVD