Total CVEs

125,674

Critical Severity

2,261

High Severity

7,825

Last 7 Days

1,180
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 621 - 640 of 22,079 CVEs
CVE-2026-7063 HIGH - 7.3

A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performing a manipulation of the argument pwd results in sql injection. The attack is possible to be carried o...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7062 HIGH - 7.3

A security vulnerability has been detected in Intina47 context-sync up to 2.0.0. This affects an unknown part of the file src/git-integration.ts of the component Git Integration. Such manipulation leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publ...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7061 HIGH - 7.3

A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exp...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7060 HIGH - 7.3

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl.java of the component MyBatis-Plus. Executing a manipulatio...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7059 MEDIUM - 5.3

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing a manipulation of the argument Platform results in path traversal. The attack can be initiated remot...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7058 HIGH - 7.3

A vulnerability has been found in 666ghj MiroFish up to 0.1.2. The impacted element is the function SimulationIPCClient.send_command of the file backend/app/services/simulation_ipc.py of the component Inter-Process Communication. Such manipulation leads to command injection. It is possible to launch...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7057 HIGH - 8.8

A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and ...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7056 HIGH - 8.8

A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be use...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7055 HIGH - 8.8

A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The ex...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7054 HIGH - 8.8

A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usernamewith can lead to buffer overflow. The attack can be executed remotely. The ex...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7053 HIGH - 8.8

A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been release...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7045 MEDIUM - 6.3

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the comp...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7044 MEDIUM - 6.3

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability ...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7043 MEDIUM - 6.3

A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be use...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7042 HIGH - 7.3

A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST API Endpoint. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been published...

Published: Apr 26, 2026
Source: NVD
CVE-2018-25297 MEDIUM - 6.2

Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads into the Camera name and DID number fields during camera addition to trigger application crashes.

Vendor: Wansview
Product: Wansview
Published: Apr 26, 2026
Source: NVD
CVE-2018-25296 MEDIUM - 5.5

P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 2000-byte payload into the password field and click login to trigger an appl...

Vendor: P10
Product: Central Management Software
Published: Apr 26, 2026
Source: NVD
CVE-2018-25295 MEDIUM - 6.2

ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers can paste a 2000-byte buffer of repeated characters into the IP field and trigger a search operation ...

Vendor: P10
Product: ObserverIP Scan Tool
Published: Apr 26, 2026
Source: NVD
CVE-2018-25294 HIGH - 7.5

CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.

Vendor: Cewe-Photoworld
Product: CEWE Photoshow
Published: Apr 26, 2026
Source: NVD
CVE-2018-25293 MEDIUM - 6.2

Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to crash the application by supplying an excessively long string in the optional proxy password field. Attackers can trigger a denial of service by entering a 6000-byte payload into ...

Vendor: Mersenne
Product: Prime95
Published: Apr 26, 2026
Source: NVD