Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
Showing 7,341 - 7,360 of 13,935 CVEs
CVE-2026-5542 MEDIUM - 4.3

A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation of the argument userid can lead to cross site scripting. The attack may be launched remotely. The expl...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5541 MEDIUM - 4.3

A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /modmemberinfo.php of the component Parameter Handler. Performing a manipulation of the argument userid results in cross site scripting. The attack may be initiated remotely. ...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5590 MEDIUM - 6.4

A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context data is passed to tcp_backlog_is_full() and dereferenced without ...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5539 MEDIUM - 4.3

A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember.php of the component Parameter Handler. This manipulation of the argument firstName causes cross site scripting. The attack can be initiated remotely. The exploit has been publish...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5538 MEDIUM - 6.3

A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_url of the component judge_server_heartbeat Endpoint. The manipulation results in server-side request forgery. It is possible to launch the attack remo...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5537 MEDIUM - 6.3

A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the component HTTP GET Parameter Handler. The manipulation of the argument seid leads to sql injection. I...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5535 MEDIUM - 4.3

A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the argument dataSet results in path traversal. The attack is possible to be carried out remotely. The ex...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5533 MEDIUM - 4.3

A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. T...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5532 MEDIUM - 6.3

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the component GenerateCodeNode Component. The manipulation results in os command injection. The attack may ...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5531 MEDIUM - 5.3

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storage in a file or on disk. The attack may be initiated remotely....

Published: Apr 05, 2026
Source: NVD
CVE-2026-5530 MEDIUM - 6.3

A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disc...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5529 MEDIUM - 4.3

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now pub...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5528 MEDIUM - 6.3

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5527 MEDIUM - 5.3

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key . It is possible to ...

Published: Apr 05, 2026
Source: NVD
CVE-2016-20054 MEDIUM - 4.3

Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administrators into submitting requests to admin/user_manipulate and admin/settings/generall endpoints to cre...

Vendor: nodcms
Product: nodCMS
Published: Apr 04, 2026
Source: NVD
CVE-2018-25253 MEDIUM - 6.2

Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. Attackers can paste a 2000-byte payload into the Settings User interface language field to crash the ap...

Vendor: Compuphase
Product: Termite
Published: Apr 04, 2026
Source: NVD
CVE-2018-25252 MEDIUM - 6.2

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP fie...

Vendor: Serv-U
Product: FTP Voyager
Published: Apr 04, 2026
Source: NVD
CVE-2018-25249 MEDIUM - 6.4

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other users view or edit th...

Vendor: MyBB
Product: MyBB My Arcade Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2018-25247 MEDIUM - 6.1

MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can craft post subjects containing script tags that execute when other users view the attacker's profil...

Vendor: MyBB
Product: MyBB Like Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2018-25244 MEDIUM - 6.2

Microsoft Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar and trigger a crash by initiat...

Vendor: EcoSearch
Product: Eco Search
Published: Apr 04, 2026
Source: NVD