Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,161 - 9,180 of 13,211 CVEs
CVE-2019-25479 HIGH - 8.2

Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the agents/agentlistdetails endpoint with malicious SQL payloads in the city parameter t...

Vendor: Inoutscripts
Product: Inout RealEstate
Published: Mar 12, 2026
Source: NVD
CVE-2019-25473 HIGH - 7.1

Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month parameter. Attackers can send POST requests to the monthly_expense_overview endpoint with crafted month values using boolean-based blind, time-...

Vendor: Softwebinternational
Product: Clinic Pro
Published: Mar 12, 2026
Source: NVD
CVE-2026-4042 HIGH - 8.8

A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made avail...

Published: Mar 12, 2026
Source: NVD
CVE-2026-4041 HIGH - 8.8

A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and m...

Published: Mar 12, 2026
Source: NVD
CVE-2026-21670 HIGH - 7.7

A vulnerability allowing a low-privileged user to extract saved SSH credentials.

Vendor: Veeam
Product: Backup and Replication
Published: Mar 12, 2026
Source: NVD
CVE-2026-21668 HIGH - 8.8

A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

Vendor: Veeam
Product: Backup and Replication
Published: Mar 12, 2026
Source: NVD
CVE-2026-31860 HIGH - 6.1

Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event handlers, into SSR-rendered <head> tags. This is the composable that Nuxt docs recommend for safely handling user-generated content. The acceptDat...

Vendor: npm
Product: unhead
Published: Mar 12, 2026
Source: GitHub
CVE-2026-3989 HIGH - 7.8

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

Vendor: pip
Product: sglang
Published: Mar 12, 2026
Source: NVD
CVE-2026-4014 HIGH - 7.3

A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the file /curvus2/signup.php of the component Registration. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible....

Vendor: luffypirates
Product: cafe_reservation_system
Published: Mar 12, 2026
Source: NVD
CVE-2026-4008 HIGH - 8.8

A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSIDset of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely...

Published: Mar 12, 2026
Source: NVD
CVE-2026-4007 HIGH - 8.8

A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. It is possible to initiate the attack remot...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3981 HIGH - 7.3

A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public...

Vendor: unguardable
Product: online_doctor_appointment_system
Published: Mar 12, 2026
Source: NVD
CVE-2026-3980 HIGH - 7.3

A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_action.php. Such manipulation of the argument patient_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the...

Vendor: unguardable
Product: online_doctor_appointment_system
Published: Mar 12, 2026
Source: NVD
CVE-2026-3978 HIGH - 8.8

A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formEasySetupWizard3. The manipulation of the argument wan_connected results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be ...

Vendor: dlink
Product: dir-513_firmware
Published: Mar 12, 2026
Source: NVD
CVE-2026-3976 HIGH - 8.8

A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch th...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3975 HIGH - 8.8

A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation of the argument wl_radio results in stack-based buffer overflow. It is possible ...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3974 HIGH - 8.8

A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be performed from remote. The...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3657 HIGH - 7.5

The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action in all versions up to, and including, 2.8.6. This is due to the handler using attacker-controlled POST parameter names directly as SQL column identifiers in `$wpdb->insert()`. ...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3973 HIGH - 8.8

A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component POST Parameter Handler. This manipulation of the argument ping1/ping2 causes stack-based buffer overflow. The attack is possible to be carried out remo...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3972 HIGH - 8.8

A vulnerability was found in Tenda W3 1.0.0.3(2204). Affected by this issue is the function formSetCfm of the file /goform/setcfm of the component HTTP Handler. The manipulation of the argument funcpara1 results in stack-based buffer overflow. The attack can only be performed from the local network....

Published: Mar 12, 2026
Source: NVD