Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,970
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,261 - 3,280 of 34,447 CVEs
CVE-2026-11488 HIGH - 7.3

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely...

Vendor: code-projects
Product: Simple Flight Ticket Booking System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11487 MEDIUM - 5.3

A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The exp...

Product: Neovim
Published: Jun 08, 2026
Source: NVD
CVE-2026-11486 HIGH - 7.3

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /archive1.php. Performing a manipulation of the argument sy results in sql injection. Remote exploitation of the attack is possible. The exploi...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11485 HIGH - 7.3

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive2.php. Such manipulation of the argument sy leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11484 HIGH - 7.3

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /archive3.php. This manipulation of the argument sy causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and c...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11483 HIGH - 7.3

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /archive4.php. The manipulation of the argument sy results in sql injection. The attack can be launched remotely. The exploit has been released to the public and ...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11482 HIGH - 7.3

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /archive5.php. The manipulation of the argument sy leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The...

Vendor: yoanbernabeu
Product: grepai
Published: Jun 08, 2026
Source: NVD
CVE-2026-11480 MEDIUM - 6.3

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. Impacted is an unknown function of the file beike/Admin/Routes/admin.php of the component Admin Design Builder Endpoint. Performing a manipulation of the argument settings.value results in sql injection. It i...

Vendor: Chengdu Everbrite Network Technology
Product: BeikeShop
Published: Jun 08, 2026
Source: NVD
CVE-2026-11479 MEDIUM - 4.2

A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manipulation leads to use of weak hash. The attack may be performed from remote. Attacks of this nature are highly complex. Th...

Vendor: yoanbernabeu
Product: grepai
Published: Jun 08, 2026
Source: NVD

A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern Handler. This manipulation causes inefficient regular expression complexity. The attack is restricted to local execu...

Vendor: kokke
Product: tiny-regex-c
Published: Jun 08, 2026
Source: NVD
CVE-2026-11477 MEDIUM - 4.3

A vulnerability was detected in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in open ...

Vendor: hs-web
Product: hsweb-framework
Published: Jun 08, 2026
Source: NVD
CVE-2026-11476 MEDIUM - 6.3

A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this issue is the function edit-admin of the file controllers/AdminController.php of the component Profile Update Endpoint. The manipulation of the argument is...

Vendor: Kushan2k
Product: student-management-system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11475 MEDIUM - 6.3

A weakness has been identified in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this vulnerability is the function getStatus of the file controllers/GradeController.php of the component Certificate Verification Endpoint. Executing a manipulation of th...

Vendor: Kushan2k
Product: student-management-system
Published: Jun 08, 2026
Source: NVD
CVE-2024-58349 CRITICAL - 9.8

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute th...

Vendor: WP Travel Kit
Product: Travelscape
Published: Jun 08, 2026
Source: NVD
CVE-2024-58348 CRITICAL - 9.8

WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to execute arbitrary co...

Vendor: background-image-cropper
Product: Background Image Cropper
Published: Jun 08, 2026
Source: NVD
CVE-2023-54352 CRITICAL - 9.8

WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands and...

Vendor: WP Travel Kit
Product: Travelscape
Published: Jun 08, 2026
Source: NVD
CVE-2023-54351 HIGH - 7.2

WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php which are stored and e...

Vendor: Sonaar
Product: Sonaar Music Plugin
Published: Jun 08, 2026
Source: NVD
CVE-2023-54350 HIGH - 7.5

WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create m...

Vendor: webandprint
Product: Augmented Reality
Published: Jun 08, 2026
Source: NVD
CVE-2022-50953 MEDIUM - 6.2

WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing di...

Vendor: brooks24
Product: admin-word-count-column
Published: Jun 08, 2026
Source: NVD