Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,810
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,481 - 5,500 of 13,509 CVEs
CVE-2026-7091 MEDIUM - 6.3

A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Management Handler. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be...

Published: Apr 27, 2026
Source: NVD
CVE-2026-42371 MEDIUM - 5.1

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

Vendor: uriparser
Product: uriparser
Published: Apr 27, 2026
Source: NVD
CVE-2026-3008 MEDIUM - 6.6

Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7089 MEDIUM - 4.3

A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the component Appointment Booking. The manipulation of the argument fname/lname leads to cross site scripting. The attack may be initiated remo...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7086 MEDIUM - 4.3

A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl of the file replaceUrl.ts of the component Storyboard Export. Such manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The expl...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7085 MEDIUM - 5.0

A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/about/downloadApp.ts of the component downloadApp Endpoint. This manipulation of the argument url causes path traversal. It is possible to initiate the at...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7084 MEDIUM - 6.3

A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeByLink.ts of the component getCodeByLink Endpoint. The manipulation of the argument Link results in server-side request forgery. The attack may be perfor...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7083 MEDIUM - 4.7

A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function queryResult of the file server\app\adminapi\lists\tools\DataTableLists.php of the component dataTable Admin API. The manipulation leads to sql injection. The attack is possible to b...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7071 MEDIUM - 5.3

A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remote exploitation of the attack is possible. The exploit has be...

Published: Apr 27, 2026
Source: NVD
CVE-2026-33566 MEDIUM - 4.3

There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.

Vendor: Japan Computer Emergency Response Team Coordination Center (JPCERT/CC)
Product: LogonTracer
Published: Apr 27, 2026
Source: NVD
CVE-2026-7059 MEDIUM - 5.3

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing a manipulation of the argument Platform results in path traversal. The attack can be initiated remot...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7045 MEDIUM - 6.3

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the comp...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7044 MEDIUM - 6.3

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability ...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7043 MEDIUM - 6.3

A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be use...

Published: Apr 26, 2026
Source: NVD
CVE-2018-25297 MEDIUM - 6.2

Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads into the Camera name and DID number fields during camera addition to trigger application crashes.

Vendor: Wansview
Product: Wansview
Published: Apr 26, 2026
Source: NVD
CVE-2018-25296 MEDIUM - 5.5

P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 2000-byte payload into the password field and click login to trigger an appl...

Vendor: P10
Product: Central Management Software
Published: Apr 26, 2026
Source: NVD
CVE-2018-25295 MEDIUM - 6.2

ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers can paste a 2000-byte buffer of repeated characters into the IP field and trigger a search operation ...

Vendor: P10
Product: ObserverIP Scan Tool
Published: Apr 26, 2026
Source: NVD
CVE-2018-25293 MEDIUM - 6.2

Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to crash the application by supplying an excessively long string in the optional proxy password field. Attackers can trigger a denial of service by entering a 6000-byte payload into ...

Vendor: Mersenne
Product: Prime95
Published: Apr 26, 2026
Source: NVD
CVE-2018-25292 MEDIUM - 6.2

Bome Restorator 1793 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can create a malicious payload exceeding 4000 bytes and paste it into the Name input field to trigger an application...

Vendor: Bome
Product: Restorator
Published: Apr 26, 2026
Source: NVD
CVE-2018-25291 MEDIUM - 6.2

Project64 2.3.2 contains a buffer overflow vulnerability in the Plugin Directory settings field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 6000-byte payload into the Plugin Directory field through the Options > Settings >...

Vendor: Pj64-Emu
Product: Project64
Published: Apr 26, 2026
Source: NVD