Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,481 - 7,500 of 12,781 CVEs
CVE-2026-5017 HIGH - 7.3

A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipulation of the argument Status results in sql injection. The attack can be initiated remotely. The ex...

Vendor: carmelo
Product: simple_food_order_system
Published: Mar 28, 2026
Source: NVD
CVE-2026-5016 HIGH - 7.3

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available a...

Published: Mar 28, 2026
Source: NVD
CVE-2026-5012 HIGH - 7.3

A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early ...

Published: Mar 28, 2026
Source: NVD
CVE-2026-5004 HIGH - 8.8

A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin/firewall.cgi of the component UPNP Handler. Executing a manipulation of the argument UpnpEnabled can lead to stack-based buffer overflow. It is possible to launch the attack remot...

Vendor: wavlink
Product: wl-wn579x3-c_firmware
Published: Mar 28, 2026
Source: NVD
CVE-2026-5002 HIGH - 7.3

A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted element is the function _route_using_overviews of the file backend/server.py of the component LLM Prompt Handler. Such manipulation leads to injection. The attack may be performed fr...

Published: Mar 28, 2026
Source: NVD
CVE-2026-5001 HIGH - 7.3

A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is the function do_POST of the file backend/server.py. This manipulation causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been published ...

Published: Mar 28, 2026
Source: NVD
CVE-2026-5000 HIGH - 7.3

A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of the file backend/server.py of the component API Endpoint. The manipulation of the argument BaseHTTPRequestHandler results in missing authentication. The ...

Published: Mar 28, 2026
Source: NVD
CVE-2026-4998 HIGH - 7.3

A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection. The attack may be lau...

Published: Mar 28, 2026
Source: NVD
CVE-2026-4996 HIGH - 7.3

A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_la...

Published: Mar 28, 2026
Source: NVD
CVE-2018-25225 HIGH - 8.4

SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the ret...

Vendor: Sipp
Product: SIPP
Published: Mar 28, 2026
Source: NVD
CVE-2018-25224 HIGH - 8.4

PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell ...

Vendor: pms
Product: PMS
Published: Mar 28, 2026
Source: NVD
CVE-2018-25222 HIGH - 8.4

SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 1052 bytes to overwrite the instruction pointer and execute shellcode...

Vendor: sc
Product: SC
Published: Mar 28, 2026
Source: NVD
CVE-2017-20228 HIGH - 8.4

Flat Assembler 1.71.21 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input to the application. Attackers can craft malicious assembly input exceeding 5895 bytes to overwrite the instruction pointer and execute return...

Vendor: Flatassembler
Product: Flat Assembler
Published: Mar 28, 2026
Source: NVD
CVE-2017-20226 HIGH - 8.4

Mapscrn 2.0.3 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized input buffer. Attackers can craft a malicious buffer with junk data, return address, NOP instructions, and shellcode to overflow the stack and achieve co...

Vendor: msk
Product: Mapscrn
Published: Mar 28, 2026
Source: NVD
CVE-2016-20048 HIGH - 8.4

iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized value to the -k/--key parameter. Attackers can craft a malicious argument containing a NOP sled, shellcode, and return address to overflow a 1024-byte sta...

Vendor: iselect
Product: iSelect
Published: Mar 28, 2026
Source: NVD
CVE-2016-20047 HIGH - 8.4

EKG Gadu 1.9~pre+r2855-3+b1 contains a local buffer overflow vulnerability in the username handling that allows local attackers to execute arbitrary code by supplying an oversized username string. Attackers can trigger the overflow in the strlcpy function by passing a crafted buffer exceeding 258 by...

Vendor: ekg
Product: EKG Gadu
Published: Mar 28, 2026
Source: NVD
CVE-2016-20046 HIGH - 8.4

zFTP Client 20061220+dfsg3-4.1 contains a buffer overflow vulnerability in the NAME parameter handling of FTP connections that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized NAME value exceeding the 80-byte buffer allocated in strcpy_chk ...

Vendor: zFTP
Product: zFTP Client
Published: Mar 28, 2026
Source: NVD
CVE-2016-20045 HIGH - 8.4

HNB Organizer 1.9.18-10 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -rc command-line parameter. Attackers can craft a malicious input string exceeding 108 bytes containing shellcode and a return addres...

Vendor: hnb
Product: HNB
Published: Mar 28, 2026
Source: NVD
CVE-2016-20044 HIGH - 8.4

PInfo 0.6.9-5.1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -m parameter. Attackers can craft a malicious input string with 564 bytes of padding followed by a return address to overwrite the instructio...

Vendor: pinfo
Product: PInfo
Published: Mar 28, 2026
Source: NVD
CVE-2016-20043 HIGH - 8.4

NRSS RSS Reader 0.3.9-1 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -F parameter. Attackers can craft a malicious input with 256 bytes of padding followed by a controlled EIP value to overwrite the ret...

Vendor: nrss
Product: NRSS Reader
Published: Mar 28, 2026
Source: NVD