Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,421 - 3,440 of 3,474 CVEs
CVE-2025-15029 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3...

Published: Jan 05, 2026
Source: NVD
CVE-2025-15026 CRITICAL - 9.8

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 bef...

Published: Jan 05, 2026
Source: NVD
CVE-2026-0592 CRITICAL - 9.8

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This affects an unknown function of the file /handgunner-administrator/register_code.php of the component User Registration Handler. Performing a manipulation of the argument fname/lname/address/city/province...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 05, 2026
Source: NVD
CVE-2026-0591 CRITICAL - 9.8

A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknown function of the file /app/checkout/update.php of the component Cart Update Handler. Such manipulation of the argument id/qty leads to sql injection. It is possible to launch the ...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 05, 2026
Source: NVD
CVE-2023-50897 CRITICAL - 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Files.This issue affects Media File Renamer: from n/a through 5.7.7.

Published: Jan 05, 2026
Source: NVD
CVE-2026-0590 CRITICAL - 9.8

A vulnerability was determined in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file /app/checkout/delete.php of the component POST Parameter Handler. This manipulation of the argument ID causes sql injection. It is possible to initiate the a...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 05, 2026
Source: NVD
CVE-2025-68865 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global allows SQL Injection.This issue affects Infility Global: from n/a through 2.14.48.

Published: Jan 05, 2026
Source: NVD
CVE-2025-31048 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through 1.1.4.

Published: Jan 05, 2026
Source: NVD
CVE-2025-30633 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3.

Published: Jan 05, 2026
Source: NVD
CVE-2026-0585 CRITICAL - 9.8

A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the file /order_view.php of the component GET Parameter Handler. Such manipulation of the argument transaction_id leads to sql injection. The attack can be executed r...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 05, 2026
Source: NVD
CVE-2026-0584 CRITICAL - 9.8

A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been mad...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 05, 2026
Source: NVD
CVE-2026-0583 CRITICAL - 9.8

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/user/login.php of the component User Login. The manipulation of the argument emailadd results in sql injection. The attack may be launched remotely. The...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 05, 2026
Source: NVD
CVE-2026-0582 CRITICAL - 9.8

A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_activity_query.php. The manipulation of the argument Title leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be u...

Vendor: angeljudesuarez
Product: society_management_system
Published: Jan 05, 2026
Source: NVD
CVE-2026-0581 CRITICAL - 9.8

A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be l...

Vendor: tenda
Product: ac1206_firmware
Published: Jan 05, 2026
Source: NVD
CVE-2025-15458 CRITICAL - 9.8

A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the attack remotely. The exploit has been publicly...

Vendor: 1234n
Product: minicms
Published: Jan 05, 2026
Source: NVD
CVE-2025-15457 CRITICAL - 9.8

A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The exp...

Vendor: 1234n
Product: minicms
Published: Jan 05, 2026
Source: NVD
CVE-2025-15447 CRITICAL - 9.8

A vulnerability has been found in Seeyon Zhiyuan OA Web Application System up to 20251223. This affects an unknown function of the file /assetsGroupReport/assetsService.j%73p. The manipulation of the argument unitCode leads to sql injection. It is possible to initiate the attack remotely. The exploi...

Vendor: seeyon
Product: oa_web_application_system
Published: Jan 05, 2026
Source: NVD
CVE-2025-15446 CRITICAL - 9.8

A flaw has been found in Seeyon Zhiyuan OA Web Application System up to 20251223. The impacted element is an unknown function of the file /assetsGroupReport/fixedAssetsList.j%73p. Executing a manipulation of the argument unitCode can lead to sql injection. The attack may be performed from remote. Th...

Vendor: seeyon
Product: oa_web_application_system
Published: Jan 04, 2026
Source: NVD
CVE-2026-0579 CRITICAL - 9.8

A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the file /handgunner-administrator/edit.php of the component POST Parameter Handler. The manipulation of the argument prod_id/name/price/model/serial results in sql injection. The attack...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 04, 2026
Source: NVD
CVE-2026-0578 CRITICAL - 9.8

A vulnerability has been found in code-projects Online Product Reservation System 1.0. Affected by this issue is some unknown functionality of the file /handgunner-administrator/delete.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit ...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 04, 2026
Source: NVD