Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,810
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,461 - 5,480 of 13,509 CVEs
CVE-2026-7118 MEDIUM - 6.3

A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation of the argument id/token leads to sql injection. The attack is possible to be carried out remotely. The exploit ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7117 MEDIUM - 6.3

A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has been made available to...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7116 MEDIUM - 4.3

A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown processing of the file 370project/mark.php. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-5942 MEDIUM - 5.5

Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.

Vendor: foxit
Product: pdf_editor
Published: Apr 27, 2026
Source: NVD
CVE-2026-5939 MEDIUM - 5.5

A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.

Vendor: foxit
Product: pdf_editor
Published: Apr 27, 2026
Source: NVD
CVE-2026-5938 MEDIUM - 5.5

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.

Vendor: foxit
Product: pdf_editor
Published: Apr 27, 2026
Source: NVD
CVE-2026-5937 MEDIUM - 5.5

Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.

Vendor: foxit
Product: pdf_editor
Published: Apr 27, 2026
Source: NVD
CVE-2026-42410 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1.

Vendor: CodexThemes
Product: TheGem Theme Elements (for Elementor)
Published: Apr 27, 2026
Source: NVD
CVE-2026-7115 MEDIUM - 6.3

A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7114 MEDIUM - 6.3

A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7113 MEDIUM - 5.6

A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be laun...

Published: Apr 27, 2026
Source: NVD
CVE-2026-27172 MEDIUM - 6.3

The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store and passed them to ObjectInputStream.readObject() without configuring an ObjectInputFilt...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Apr 27, 2026
Source: NVD
CVE-2026-7112 MEDIUM - 5.6

A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to improper authentication. The attack can be initiated remotely. ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7109 MEDIUM - 5.3

A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and ma...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7108 MEDIUM - 4.3

A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7107 MEDIUM - 6.3

A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available t...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7102 MEDIUM - 6.3

A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the argument mac results in command injection. The attack can be executed remotely. The exploit has been made public and could be use...

Vendor: tenda
Product: f456_firmware
Published: Apr 27, 2026
Source: NVD
CVE-2026-7095 MEDIUM - 4.3

A vulnerability was identified in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7093 MEDIUM - 6.3

A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be c...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7092 MEDIUM - 6.3

A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The exploit has been discl...

Published: Apr 27, 2026
Source: NVD