Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,297
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,041 - 7,060 of 12,776 CVEs
CVE-2026-5562 HIGH - 7.3

A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code injection. The attack can be initiated remotely. The exploit is publicly available and mig...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5555 HIGH - 7.3

A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack ma...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5554 HIGH - 7.3

A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searchi...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5551 HIGH - 7.3

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. The manipulation of the argument email results in sql injection. The attack may be launched remotely. ...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5550 HIGH - 8.8

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.

Published: Apr 05, 2026
Source: NVD
CVE-2026-5548 HIGH - 8.8

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.

Published: Apr 05, 2026
Source: NVD
CVE-2026-5544 HIGH - 8.8

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument Profile results in stack-based buffer overflow. The attack can be executed remotely. The exploit has ...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5540 HIGH - 7.3

A vulnerability has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modifymember.php of the component Parameter Handler. Such manipulation of the argument firstName leads to sql injection. The attack can be launched remotely. The exploit ha...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5536 HIGH - 7.3

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclos...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5534 HIGH - 7.3

A vulnerability was identified in itsourcecode Online Enrollment System 1.0. This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the component Parameter Handler. Such manipulation of the argument USERID leads to sql injection. The attack can be executed remotely. ...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5526 HIGH - 7.3

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been released...

Published: Apr 04, 2026
Source: NVD
CVE-2018-25246 HIGH - 7.5

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated characters into the search bar to trigger an application crash.

Vendor: Wikipedia
Product: Wikipedia
Published: Apr 04, 2026
Source: NVD
CVE-2018-25255 HIGH - 8.4

10-Strike LANState 8.8 contains a local buffer overflow vulnerability in structured exception handling that allows local attackers to execute arbitrary code by crafting malicious LSM map files. Attackers can create a specially formatted LSM file with a payload in the ObjCaption parameter that overfl...

Vendor: 10-Strike
Product: Strike LANState
Published: Apr 04, 2026
Source: NVD
CVE-2018-25251 HIGH - 8.4

Snes9K 0.0.9z contains a buffer overflow vulnerability in the Netplay Socket Port Number field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Socket Port Number field via the Netplay Options menu to...

Vendor: Sourceforge
Product: Snes9K 0.0.9z
Published: Apr 04, 2026
Source: NVD
CVE-2018-25250 HIGH - 7.2

MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags. Attackers can create threads with script payloads in the subject field that execute when users ...

Vendor: MyBB
Product: MyBB Last User's Threads in Profile Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2018-25248 HIGH - 7.2

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators vali...

Vendor: MyBB
Product: MyBB Downloads Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2018-25245 HIGH - 7.5

Microsoft 7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 7700 characters into the search bar to trigger an application crash.

Vendor: 7Tik
Product: 7 Tik
Published: Apr 04, 2026
Source: NVD
CVE-2018-25241 HIGH - 7.5

Microsoft VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled except...

Vendor: VPNBrowser
Product: VPN Browser+
Published: Apr 04, 2026
Source: NVD
CVE-2016-20061 HIGH - 7.8

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execu...

Vendor: Sheedantivirus
Product: sheed AntiVirus
Published: Apr 04, 2026
Source: NVD
CVE-2016-20060 HIGH - 7.8

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious co...

Vendor: Hotspotshield
Product: Hotspot Shield
Published: Apr 04, 2026
Source: NVD