Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,281 - 3,300 of 34,478 CVEs
CVE-2026-3238 HIGH - 7.5

A flaw was found in Sambaโ€™s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WI...

Published: Jun 08, 2026
Source: NVD
CVE-2026-11499 CRITICAL - 9.8

A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote.

Vendor: Tenda
Product: HG7HG9, HG10
Published: Jun 08, 2026
Source: NVD
CVE-2026-11498 HIGH - 8.8

A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overf...

Vendor: Tenda
Product: HG7HG9, HG10
Published: Jun 08, 2026
Source: NVD
CVE-2026-11497 MEDIUM - 5.3

A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been d...

Vendor: D-Link
Product: DCS-5615
Published: Jun 08, 2026
Source: NVD
CVE-2026-11495 MEDIUM - 6.3

A vulnerability was detected in CodeAstro Ingredients Stock Management System 1.0. This impacts an unknown function of the file /Ingredients-Stock/add_stock.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be us...

Vendor: CodeAstro
Product: Ingredients Stock Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11494 MEDIUM - 4.3

A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and...

Vendor: TOTOLINK
Product: AC1200 T8
Published: Jun 08, 2026
Source: NVD
CVE-2026-11493 MEDIUM - 5.0

A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements. The attack is only possible within the local network. A high complexity level is...

Vendor: Tenda
Product: AC15
Published: Jun 08, 2026
Source: NVD
CVE-2026-11492 MEDIUM - 4.3

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to th...

Vendor: D-Link
Product: DIR-823G
Published: Jun 08, 2026
Source: NVD

A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Trigger...

Vendor: CodeAstro
Product: Human Resource Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11490 HIGH - 7.3

A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed...

Vendor: code-projects
Product: Online Music Site
Published: Jun 08, 2026
Source: NVD
CVE-2026-11489 HIGH - 7.3

A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and c...

Vendor: code-projects
Product: Online Music Site
Published: Jun 08, 2026
Source: NVD
CVE-2026-11488 HIGH - 7.3

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely...

Vendor: code-projects
Product: Simple Flight Ticket Booking System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11487 MEDIUM - 5.3

A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The exp...

Product: Neovim
Published: Jun 08, 2026
Source: NVD
CVE-2026-11486 HIGH - 7.3

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /archive1.php. Performing a manipulation of the argument sy results in sql injection. Remote exploitation of the attack is possible. The exploi...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11485 HIGH - 7.3

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive2.php. Such manipulation of the argument sy leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11484 HIGH - 7.3

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /archive3.php. This manipulation of the argument sy causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and c...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11483 HIGH - 7.3

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /archive4.php. The manipulation of the argument sy results in sql injection. The attack can be launched remotely. The exploit has been released to the public and ...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11482 HIGH - 7.3

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /archive5.php. The manipulation of the argument sy leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The...

Vendor: yoanbernabeu
Product: grepai
Published: Jun 08, 2026
Source: NVD
CVE-2026-11480 MEDIUM - 6.3

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. Impacted is an unknown function of the file beike/Admin/Routes/admin.php of the component Admin Design Builder Endpoint. Performing a manipulation of the argument settings.value results in sql injection. It i...

Vendor: Chengdu Everbrite Network Technology
Product: BeikeShop
Published: Jun 08, 2026
Source: NVD