Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,796
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,001 - 9,020 of 13,059 CVEs
CVE-2019-25512 HIGH - 8.2

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST requests. Attackers can manipulate the kelime parameter with UNION-based SQL injection payloads to extract sensitive database ...

Vendor: Jettweb
Product: Hazir Haber Sitesi Scripti
Published: Mar 12, 2026
Source: NVD
CVE-2019-25511 HIGH - 8.2

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the videoid parameter. Attackers can send GET requests to fonksiyonlar.php with malicious videoid values using UNION-ba...

Vendor: Jettweb
Product: Hazir Haber Sitesi Scripti
Published: Mar 12, 2026
Source: NVD
CVE-2019-25510 HIGH - 8.2

Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative access by exploiting improper SQL query validation. Attackers can submit SQL injection payloads in the username and passw...

Vendor: Jettweb
Product: Hazir Haber Sitesi Scripti
Published: Mar 12, 2026
Source: NVD
CVE-2019-25509 HIGH - 8.2

XooDigital Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to extract sensitive database i...

Vendor: Xooscripts
Product: XooDigital
Published: Mar 12, 2026
Source: NVD
CVE-2019-25508 HIGH - 8.2

Jettweb Php Hazir Ilan Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'kat' parameter. Attackers can send GET requests to the katgetir.php endpoint with malicious 'kat...

Vendor: Jettweb
Product: Hazir Ilan Sitesi Scripti
Published: Mar 12, 2026
Source: NVD
CVE-2019-25488 HIGH - 8.2

Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into the 'tur', 'id', and 'ozellikdil' parame...

Vendor: Jettweb
Product: Rent A Car Scripti
Published: Mar 12, 2026
Source: NVD
CVE-2019-25482 HIGH - 8.2

Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the arac_kategori_id parameter. Attackers can send POST requests to the endpoint with malicious SQL payloads to ex...

Vendor: Jettweb
Product: Hazir Rent A Car Sitesi Scripti
Published: Mar 12, 2026
Source: NVD
CVE-2019-25481 HIGH - 8.2

iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive d...

Vendor: Iscripts
Product: iScripts ReserveLogic
Published: Mar 12, 2026
Source: NVD
CVE-2019-25479 HIGH - 8.2

Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the agents/agentlistdetails endpoint with malicious SQL payloads in the city parameter t...

Vendor: Inoutscripts
Product: Inout RealEstate
Published: Mar 12, 2026
Source: NVD
CVE-2019-25473 HIGH - 7.1

Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month parameter. Attackers can send POST requests to the monthly_expense_overview endpoint with crafted month values using boolean-based blind, time-...

Vendor: Softwebinternational
Product: Clinic Pro
Published: Mar 12, 2026
Source: NVD
CVE-2026-4042 HIGH - 8.8

A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made avail...

Published: Mar 12, 2026
Source: NVD
CVE-2026-4041 HIGH - 8.8

A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and m...

Published: Mar 12, 2026
Source: NVD
CVE-2026-21670 HIGH - 7.7

A vulnerability allowing a low-privileged user to extract saved SSH credentials.

Vendor: Veeam
Product: Backup and Replication
Published: Mar 12, 2026
Source: NVD
CVE-2026-21668 HIGH - 8.8

A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

Vendor: Veeam
Product: Backup and Replication
Published: Mar 12, 2026
Source: NVD
CVE-2026-31860 HIGH - 6.1

Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event handlers, into SSR-rendered <head> tags. This is the composable that Nuxt docs recommend for safely handling user-generated content. The acceptDat...

Vendor: npm
Product: unhead
Published: Mar 12, 2026
Source: GitHub
CVE-2026-3989 HIGH - 7.8

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

Vendor: pip
Product: sglang
Published: Mar 12, 2026
Source: NVD
CVE-2026-4014 HIGH - 7.3

A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the file /curvus2/signup.php of the component Registration. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible....

Vendor: luffypirates
Product: cafe_reservation_system
Published: Mar 12, 2026
Source: NVD
CVE-2026-4008 HIGH - 8.8

A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSIDset of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely...

Published: Mar 12, 2026
Source: NVD
CVE-2026-4007 HIGH - 8.8

A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. It is possible to initiate the attack remot...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3981 HIGH - 7.3

A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public...

Vendor: unguardable
Product: online_doctor_appointment_system
Published: Mar 12, 2026
Source: NVD