Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,766
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,341 - 7,360 of 36,556 CVEs
CVE-2018-25389 HIGH - 8.2

HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based blind payl...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25388 HIGH - 8.8

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary ...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25387 MEDIUM - 5.3

HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25386 HIGH - 8.2

HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated use...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25385 HIGH - 8.2

E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai ...

Vendor: eregistrasi-kejuaraan-silat
Product: Registrasi Pencak Silat
Published: May 29, 2026
Source: NVD
CVE-2018-25384 MEDIUM - 5.4

Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HTML in the reply_text parameter. Attackers can post comments containing JavaScript code through the rpc.php endpoint that executes in other users'...

Vendor: wikidforum
Product: Wikidforum
Published: May 29, 2026
Source: NVD
CVE-2018-25383 HIGH - 8.4

Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA file that triggers the overflow when loaded through the Convert ...

Vendor: Commentcamarche
Product: Free MP3 CD Ripper
Published: May 29, 2026
Source: NVD
CVE-2018-25382 HIGH - 8.2

Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table names, column names...

Vendor: Bylancer
Product: Zechat
Published: May 29, 2026
Source: NVD
CVE-2026-44495 HIGH - 7.0

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affecte...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub
CVE-2026-44494 HIGH - 8.7

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-th...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub
CVE-2026-44492 HIGH - 8.6

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe)...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub
CVE-2026-44490 MEDIUM - 4.8

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the p...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.use...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub

Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escapin...

Vendor: composer
Product: froxlor/froxlor
Published: May 29, 2026
Source: GitHub
CVE-2026-41236 HIGH - 8.8

Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` under a customer-controlled home directory without ...

Vendor: composer
Product: froxlor/froxlor
Published: May 29, 2026
Source: GitHub
CVE-2026-41235 HIGH - 8.8

Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when processing add or edit requ...

Vendor: composer
Product: froxlor/froxlor
Published: May 29, 2026
Source: GitHub
CVE-2026-4290 CRITICAL - 9.1

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete(...

Published: May 29, 2026
Source: NVD
CVE-2026-39292 HIGH - 7.3

Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and...

Published: May 29, 2026
Source: NVD
CVE-2026-10063 HIGH - 8.8

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and mi...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 29, 2026
Source: NVD
CVE-2026-10062 HIGH - 8.8

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. The attack is possible to be carried out remotely. The ex...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 29, 2026
Source: NVD