Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,266
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,141 - 4,160 of 33,692 CVEs

SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control over the database. This issue affects SOPlanning version 1.55 and below.

Vendor: SOPlanning
Product: SOPlanning
Published: Jun 01, 2026
Source: NVD

SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue affects SOPlanning version 1.55 and below.

Vendor: SOPlanning
Product: SOPlanning
Published: Jun 01, 2026
Source: NVD

SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a malicious user.csv file with embedded JavaScript. The injected code is executed in the vi...

Vendor: SOPlanning
Product: SOPlanning
Published: Jun 01, 2026
Source: NVD

SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the config.csv file, which includes additional sensitive...

Vendor: SOPlanning
Product: SOPlanning
Published: Jun 01, 2026
Source: NVD
CVE-2026-32325 HIGH - 7.8

Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.

Vendor: Fsas Technologies Inc.
Product: ServerView Agents for Windows
Published: Jun 01, 2026
Source: NVD
CVE-2026-27788 HIGH - 7.8

Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.

Vendor: Fsas Technologies Inc.
Product: ServerView Agents for Windows
Published: Jun 01, 2026
Source: NVD
CVE-2026-10517 MEDIUM - 5.8

A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. When PSK authentication is not configured (opt-in, not enforced by default), an unauthenticated attacker can submit a manifest with ...

Vendor: Red Hat
Product: Red Hat Quay 3
Published: Jun 01, 2026
Source: NVD
CVE-2026-10243 HIGH - 7.3

A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be u...

Vendor: code-projects
Product: Smart Parking System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10242 MEDIUM - 6.3

A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument topic_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the pu...

Vendor: itsourcecode
Product: Content Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10241 MEDIUM - 6.3

A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2DiskFromNet of the file /airag/app/debug of the component Cloud Instance Metadata Endpoint. The manipulation results in server-side request forgery. The ...

Vendor: jeecgboot
Product: The server processes these URLs
Published: Jun 01, 2026
Source: NVD
CVE-2026-10240 MEDIUM - 6.3

A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available...

Product: JeecgBoot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10239 MEDIUM - 6.3

A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publicly disclosed and may be util...

Product: JeecgBoot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10237 MEDIUM - 4.7

A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user of the component User Management Module. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack...

Vendor: SourceCodester
Product: Water Billing Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10236 HIGH - 7.3

A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be launched remotely. Th...

Vendor: SourceCodester
Product: Water Billing Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-45192 MEDIUM - 6.5

A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not present in the redaction allowlist (`DEFAULT_SENSI...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Jun 01, 2026
Source: NVD
CVE-2026-35563 HIGH - 8.5

It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code validates the certificate chain against a trusted authority, the absence of endpoint identification allows a valid certifi...

Vendor: Apache Software Foundation
Product: Apache Directory LDAP API
Published: Jun 01, 2026
Source: NVD
CVE-2026-10235 MEDIUM - 6.3

A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the argument txt_search_category causes sql injection. The attack may be initiated remotely. The exploit has been...

Vendor: CodeAstro
Product: Ingredients Stock Management System
Published: Jun 01, 2026
Source: NVD

A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the component Campaign Handler. The manipulation of the argument content results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be use...

Vendor: Mettle
Product: sendportal
Published: Jun 01, 2026
Source: NVD

A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString leads to out-of-bounds read. The attack needs to ...

Product: Assimp
Published: Jun 01, 2026
Source: NVD
CVE-2026-10232 MEDIUM - 5.3

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made availab...

Product: Assimp
Published: Jun 01, 2026
Source: NVD