Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

959
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,441 - 6,460 of 12,679 CVEs
CVE-2026-28704 HIGH - 7.8

Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed with the privilege of the user invoking EmoCheck.

Vendor: Japan Computer Emergency Response Team Coordination Center (JPCERT/CC)
Product: Emocheck
Published: Apr 10, 2026
Source: NVD
CVE-2026-6024 HIGH - 7.3

A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be ut...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6016 HIGH - 8.8

A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The ...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6015 HIGH - 8.8

A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. T...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6014 HIGH - 8.8

A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. It is possible to initiate the attack remotely. The exploit has...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6013 HIGH - 8.8

A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit ...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6012 HIGH - 8.8

A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6004 HIGH - 7.3

A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Performing a manipulation of the argument cat_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may...

Published: Apr 10, 2026
Source: NVD
CVE-2026-4351 HIGH - 8.1

The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This is due to the `PMCS::action_handler()` method processing the bulk action `activate`/`deactivate` handlers without any authorization check or nonce verif...

Published: Apr 10, 2026
Source: NVD
CVE-2026-3360 HIGH - 7.5

The Tutor LMS โ€“ eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authentication and authorization checks in the `pay_incomplete_order()` function. The function accepts an...

Published: Apr 10, 2026
Source: NVD
CVE-2026-25203 HIGH - 7.8

Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1.

Vendor: Samsung Electronics
Product: MagicINFO 9 Server
Published: Apr 10, 2026
Source: NVD
CVE-2026-5992 HIGH - 8.8

A vulnerability was determined in Tenda F451 1.0.0.7. This affects the function fromP2pListFilter of the file /goform/P2pListFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and m...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5991 HIGH - 8.8

A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5990 HIGH - 8.8

A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function fromSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclos...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5989 HIGH - 8.8

A flaw has been found in Tenda F451 1.0.0.7. Affected is the function fromRouteStatic of the file /goform/RouteStatic. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

Published: Apr 10, 2026
Source: NVD
CVE-2026-5988 HIGH - 8.8

A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argument mit_ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be use...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5985 HIGH - 7.3

A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /crud.php. The manipulation of the argument user_Id results in sql injection. The attack may be performed from remote. The exploit has been released to the pub...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5984 HIGH - 8.8

A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is pu...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5983 HIGH - 8.8

A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Executing a manipulation of the argument curTime can lead to buffer overflow. The attack can be executed remotely. The exploit...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5982 HIGH - 8.8

A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing a manipulation of the argument curTime results in buffer overflow. Remote exploitation of the attack is po...

Published: Apr 09, 2026
Source: NVD