Total CVEs

125,663

Critical Severity

2,261

High Severity

7,819

Last 7 Days

1,181
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 481 - 500 of 22,068 CVEs
CVE-2026-7140 CRITICAL - 9.8

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument HTTP leads to os command injection. The attack may be performed from remote. The exploit has be...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7139 CRITICAL - 9.8

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mode causes os command injection. The attack is possible to be carried out remotely. The exp...

Published: Apr 27, 2026
Source: NVD
CVE-2026-38936 MEDIUM - 6.1

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

Published: Apr 27, 2026
Source: NVD
CVE-2026-38935 MEDIUM - 6.1

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter

Published: Apr 27, 2026
Source: NVD
CVE-2026-38934 HIGH - 8.8

Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php

Published: Apr 27, 2026
Source: NVD
CVE-2026-30462 MEDIUM - 4.3

A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal.

Published: Apr 27, 2026
Source: NVD
CVE-2026-30346 MEDIUM - 4.3

An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7138 CRITICAL - 9.8

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument tz results in os command injection. The attack can be executed remotely. The exploit...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7137 CRITICAL - 9.8

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument sambaEnabled leads to os command injection. Remote exploitation of the attack is...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7136 CRITICAL - 9.8

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wanIdx can lead to os command injection. The attack may be launched remotel...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7135 MEDIUM - 5.3

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attac...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7134 MEDIUM - 4.7

A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit is publicly available and might be ...

Published: Apr 27, 2026
Source: NVD

authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) differs from their UID, either because the account was created with authd prior to version 0.5.4 or because the primary group was ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-41467 MEDIUM - 5.4

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict HTML and HTM file uploads. Authenticated attackers can upload HTML files containing arbitrary JavaScript through the im...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41466 MEDIUM - 5.4

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by only detecting specific patterns while returning unsanitized strings without output encoding. Attackers can...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41465 MEDIUM - 6.5

ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequence...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41464 MEDIUM - 6.5

ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data belonging to other users including password hashes and API keys. Attackers can bypass access con...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41463 HIGH - 8.8

ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outside the intended extraction directory by crafting ZIP archives with directory traversal sequences. At...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41462 CRITICAL - 9.8

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username fie...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-30352 CRITICAL - 9.8

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

Published: Apr 27, 2026
Source: NVD