Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,636
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,281 - 7,300 of 13,554 CVEs
CVE-2026-5641 MEDIUM - 6.3

A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-image1.php of the component Parameter Handler. The manipulation of the argument filename results in sql injection. The attack may be performed from remote...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5640 MEDIUM - 6.3

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5639 MEDIUM - 6.3

A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The explo...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5638 MEDIUM - 5.3

A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem earl...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5636 MEDIUM - 6.3

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection. The attack may be initiated remotely. The exploit has been made a...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5635 MEDIUM - 6.3

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection. The attack can be launc...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5630 MEDIUM - 4.3

A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5625 MEDIUM - 4.3

A weakness has been identified in assafelovic gpt-researcher up to 3.4.3. This issue affects some unknown processing of the file gpt_researcher/skills/researcher.py of the component WebSocket Interface. Executing a manipulation of the argument task can lead to cross site scripting. The attack may be...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5624 MEDIUM - 4.3

A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Up...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5623 MEDIUM - 6.3

A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available a...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5621 MEDIUM - 5.3

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. Th...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5620 MEDIUM - 6.3

A vulnerability has been found in itsourcecode Construction Management System 1.0. Affected is an unknown function of the file /borrowed_equip_report.php of the component Parameter Handler. The manipulation of the argument Home leads to sql injection. It is possible to initiate the attack remotely. ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5619 MEDIUM - 5.3

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lead to os command injection. The attack requires local access. Th...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5618 MEDIUM - 5.6

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5615 MEDIUM - 4.3

A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5607 MEDIUM - 6.3

A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src/handlers.ts of the component URL Parameter Handler. The manipulation of the argument request.params.name/request.params.arguments leads to server-side...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5606 MEDIUM - 6.3

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /order-details.php of the component Parameter Handler. The manipulation of the argument orderid results in sql injection. It is possible to launch the attack ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5603 MEDIUM - 5.3

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used....

Vendor: npm
Product: @elgentos/magento2-dev-mcp
Published: Apr 05, 2026
Source: NVD
CVE-2026-5602 MEDIUM - 5.3

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local acc...

Vendor: npm
Product: @nor2/heim-mcp
Published: Apr 05, 2026
Source: NVD
CVE-2026-5601 MEDIUM - 5.3

A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public an...

Published: Apr 05, 2026
Source: NVD