Total CVEs

141,292

Critical Severity

3,799

High Severity

13,738

Last 7 Days

1,855
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 881 - 900 of 37,697 CVEs
CVE-2026-13563 HIGH - 8.8

A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely...

Vendor: Edimax
Product: EW-7478APC
Published: Jun 29, 2026
Source: NVD
CVE-2026-13562 HIGH - 8.8

A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. It is possible to initiate the attack remotely. The exploit ha...

Vendor: Edimax
Product: EW-7478APC
Published: Jun 29, 2026
Source: NVD
CVE-2026-13561 MEDIUM - 6.3

A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack may be performed from remote. The...

Vendor: Edimax
Product: EW-7478APC
Published: Jun 29, 2026
Source: NVD
CVE-2026-13560 MEDIUM - 6.3

A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept of the component POST Request Handler. The manipulation of the argument submit-url leads to os command injection. The attack is possible to be carried ...

Vendor: Edimax
Product: EW-7478APC
Published: Jun 29, 2026
Source: NVD
CVE-2026-13559 HIGH - 7.3

A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to th...

Vendor: code-projects
Product: Real State Services
Published: Jun 29, 2026
Source: NVD

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of t...

Vendor: CodeAstro
Product: Complaint Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-57346 HIGH - 7.1

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.

Vendor: Epiphyt
Product: Embed Privacy
Published: Jun 29, 2026
Source: NVD
CVE-2026-25707 HIGH - 8.8

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

Vendor: SUSE
Product: libzypp
Published: Jun 29, 2026
Source: NVD
CVE-2026-13601 HIGH - 7.1

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-contro...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 29, 2026
Source: NVD
CVE-2026-13557 MEDIUM - 4.3

A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site scripting. The attack may...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13556 MEDIUM - 4.3

A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The attack may be initiat...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13555 HIGH - 7.3

A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit ...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13554 MEDIUM - 4.3

A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name leads to cross site sc...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13553 HIGH - 7.3

A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The expl...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13552 HIGH - 7.3

A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the argument amen_id results in sql injection. It is possible to initiate the attack remotely. T...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD

Eclipse tinydtls before commitΒ b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate handshake message with a spe...

Published: Jun 29, 2026
Source: NVD
CVE-2026-57966 MEDIUM - 4.4

A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 29, 2026
Source: NVD
CVE-2026-57965 MEDIUM - 5.1

A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 29, 2026
Source: NVD
CVE-2026-57676 MEDIUM - 4.3

Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.

Vendor: Matteo Manna
Product: Simple User Avatar
Published: Jun 29, 2026
Source: NVD
CVE-2026-22078 HIGH - 7.3

Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.

Vendor: OPPO
Product: O+ Connect
Published: Jun 29, 2026
Source: NVD