Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

959
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,781 - 7,800 of 35,348 CVEs
CVE-2026-48845 MEDIUM - 6.5

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48844 HIGH - 7.5

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48843 HIGH - 7.2

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for...

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48842 HIGH - 8.1

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-24546 MEDIUM - 5.3

Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3.

Vendor: Ruben Garcia
Product: GamiPress
Published: May 25, 2026
Source: NVD
CVE-2026-9483 MEDIUM - 6.3

A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization. The attack may be initiated remotely. The exploit has been made public and...

Published: May 25, 2026
Source: NVD
CVE-2026-9482 HIGH - 8.8

A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be...

Published: May 25, 2026
Source: NVD
CVE-2026-9481 HIGH - 8.8

A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was co...

Published: May 25, 2026
Source: NVD
CVE-2026-9480 HIGH - 8.8

A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and ma...

Published: May 25, 2026
Source: NVD
CVE-2026-9479 HIGH - 8.8

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been...

Published: May 25, 2026
Source: NVD
CVE-2026-9478 CRITICAL - 9.8

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed ...

Published: May 25, 2026
Source: NVD
CVE-2026-9477 CRITICAL - 9.8

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is pos...

Published: May 25, 2026
Source: NVD
CVE-2026-9476 CRITICAL - 9.8

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be execut...

Published: May 25, 2026
Source: NVD
CVE-2026-9475 CRITICAL - 9.8

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is poss...

Published: May 25, 2026
Source: NVD
CVE-2026-9474 HIGH - 7.3

A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the function confirm_logged_in of the file /studentdel.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotel...

Published: May 25, 2026
Source: NVD
CVE-2026-9473 MEDIUM - 6.3

A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The e...

Published: May 25, 2026
Source: NVD
CVE-2026-9472 MEDIUM - 6.3

A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. ...

Published: May 25, 2026
Source: NVD
CVE-2026-9471 LOW - 3.5

A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file /student.php. Performing a manipulation of the argument FIRST_NAME results in cross site scripting. The attack can be initiated remotely. Th...

Published: May 25, 2026
Source: NVD
CVE-2026-27768 MEDIUM - 6.6

SQL Injection affecting the Access Manager role.

Vendor: Genetec Inc.
Product: Genetec Security Center
Published: May 25, 2026
Source: NVD
CVE-2026-9470 HIGH - 7.3

A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the function confirm_logged_in of the file student_trans.php. Such manipulation of the argument FIRST_NAME/Last_Name/EMAIL leads to sql injection. It is possi...

Published: May 25, 2026
Source: NVD