Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,441 - 3,460 of 3,474 CVEs
CVE-2026-0577 CRITICAL - 9.8

A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /handgunner-administrator/prod.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit h...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 04, 2026
Source: NVD
CVE-2026-0576 CRITICAL - 9.8

A vulnerability was detected in code-projects Online Product Reservation System 1.0. Affected is an unknown function of the file /handgunner-administrator/prod.php of the component Parameter Handler. Performing manipulation of the argument cat/price/name/model/serial results in sql injection. It is ...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 04, 2026
Source: NVD
CVE-2026-0575 CRITICAL - 9.8

A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unknown function of the file /handgunner-administrator/adminlogin.php of the component Administrator Login. Such manipulation of the argument emailadd/pass leads to sql injection. The a...

Vendor: fabian
Product: online_product_reservation_system
Published: Jan 04, 2026
Source: NVD
CVE-2026-21450 CRITICAL - 9.8

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.

Vendor: webkul
Product: bagisto
Published: Jan 02, 2026
Source: NVD
CVE-2026-21448 CRITICAL - 9.8

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.3...

Vendor: webkul
Product: bagisto
Published: Jan 02, 2026
Source: NVD
CVE-2026-21446 CRITICAL - 9.8

Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exploitable without any authentication. An attacker c...

Vendor: webkul
Product: bagisto
Published: Jan 02, 2026
Source: NVD
CVE-2026-21445 CRITICAL - 9.1

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, a...

Vendor: langflow
Product: langflow
Published: Jan 02, 2026
Source: NVD
CVE-2026-21430 CRITICAL - 9.3

Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scrip...

Vendor: emlog
Product: emlog
Published: Jan 02, 2026
Source: NVD
CVE-2026-0570 CRITICAL - 9.8

A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend/Feedback.php. Performing manipulation of the argument fname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

Vendor: fabian
Product: online_music_site
Published: Jan 02, 2026
Source: NVD
CVE-2026-0569 CRITICAL - 9.8

A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public a...

Vendor: fabian
Product: online_music_site
Published: Jan 02, 2026
Source: NVD
CVE-2026-0568 CRITICAL - 9.8

A flaw has been found in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Frontend/ViewSongs.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

Vendor: fabian
Product: online_music_site
Published: Jan 02, 2026
Source: NVD
CVE-2026-0567 CRITICAL - 9.8

A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Vendor: code-projects
Product: content_management_system
Published: Jan 02, 2026
Source: NVD
CVE-2026-0566 CRITICAL - 9.8

A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_posts.php. The manipulation of the argument image leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been d...

Vendor: code-projects
Product: content_management_system
Published: Jan 02, 2026
Source: NVD
CVE-2025-67268 CRITICAL - 9.8

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied satellite count against the size of the skyview ...

Vendor: gpsd_project
Product: gpsd
Published: Jan 02, 2026
Source: NVD
CVE-2025-59389 CRITICAL - 9.8

An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: Hyper Data Protector 2.2.4.1 and later

Vendor: qnap
Product: hyper_data_protector
Published: Jan 02, 2026
Source: NVD
CVE-2025-11837 CRITICAL - 9.8

An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later

Vendor: qnap
Product: malware_remover
Published: Jan 02, 2026
Source: NVD
CVE-2025-65125 CRITICAL - 9.8

SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive information.

Vendor: gosaliajainam
Product: online-movie-booking
Published: Jan 02, 2026
Source: NVD
CVE-2026-0565 CRITICAL - 9.8

A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available to t...

Vendor: code-projects
Product: content_management_system
Published: Jan 02, 2026
Source: NVD
CVE-2026-0546 CRITICAL - 9.8

A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipulation of the argument Value causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be ...

Vendor: code-projects
Product: content_management_system
Published: Jan 02, 2026
Source: NVD
CVE-2025-15436 CRITICAL - 9.8

A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be ...

Vendor: yonyou
Product: ksoa
Published: Jan 02, 2026
Source: NVD