Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,661 - 9,680 of 13,221 CVEs
CVE-2018-25167 HIGH - 8.2

Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit malicious SQL code through the login POST parameter to extract database information including usernames, pa...

Vendor: Net-Billetterie
Product: Billetterie
Published: Mar 06, 2026
Source: NVD
CVE-2018-25166 HIGH - 8.2

Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to index.php with crafted SQL payloads in the search parameter to extract...

Vendor: Sourceforge
Product: Meneame English Pligg
Published: Mar 06, 2026
Source: NVD
CVE-2018-25165 HIGH - 7.1

Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'type' parameter. Attackers can send POST requests to ads.php with crafted SQL payloads in the type parameter to e...

Vendor: Galaxy
Product: Galaxy Forces MMORPG
Published: Mar 06, 2026
Source: NVD
CVE-2018-25164 HIGH - 7.5

EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send GET requests to the files directory to download database files like db.sq3 containing application da...

Vendor: Phpmassmail
Product: EverSync
Published: Mar 06, 2026
Source: NVD
CVE-2018-25163 HIGH - 8.2

BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extra...

Vendor: Bitzoom
Product: BitZoom
Published: Mar 06, 2026
Source: NVD
CVE-2018-25161 HIGH - 8.2

Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting malicious code through the txtCustomerCode, txtCustomerName, and txtPhone POST parameters in SearchCustomer.php. Attackers can submit crafted SQL statements us...

Vendor: Warrantytrack
Product: Warranty Tracking System
Published: Mar 06, 2026
Source: NVD
CVE-2026-3589 HIGH - 7.5

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.

Published: Mar 06, 2026
Source: NVD
CVE-2026-29068 HIGH - 7.5

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided frames can hold. This issue has been patched in version 2.17.

Vendor: pjsip
Product: pjproject
Published: Mar 06, 2026
Source: NVD
CVE-2026-28799 HIGH - 7.5

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been pat...

Vendor: pjsip
Product: pjproject
Published: Mar 06, 2026
Source: NVD
CVE-2026-28787 HIGH - 8.2

OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client request body during verifi...

Vendor: OneUptime
Product: oneuptime
Published: Mar 06, 2026
Source: NVD
CVE-2026-28679 HIGH - 8.6

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a download, the application does not verify whether the requested file is located within the media source directory, which can result in sensitive system file...

Vendor: xemle
Product: home-gallery
Published: Mar 06, 2026
Source: NVD
CVE-2026-28677 HIGH - 8.2

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, the URL ingest pipeline accepted user-controlled remote URLs with incomplete destination restrictions. Although private/local host checks existed, missing restriction...

Vendor: OpenSift
Product: OpenSift
Published: Mar 06, 2026
Source: NVD
CVE-2026-28676 HIGH - 8.8

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers used path construction patterns that did not uniformly enforce base-directory containment. This created path-injection risk in file read/writ...

Vendor: OpenSift
Product: OpenSift
Published: Mar 06, 2026
Source: NVD
CVE-2026-28429 HIGH - 7.5

Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified in the gameName parameter. While the application's primary entry points implement input validation, the ParseGamestate.php component can be accessed directly as a standalone sc...

Vendor: Talishar
Product: Talishar
Published: Mar 06, 2026
Source: NVD
CVE-2026-27603 HIGH - 7.5

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the chart filter endpoint POST /project/:project_id/chart/:chart_id/filter is missing both verifyToken and checkPermissions middleware, allowing unau...

Vendor: chartbrew
Product: chartbrew
Published: Mar 06, 2026
Source: NVD
CVE-2026-25888 HIGH - 8.8

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via a vulnerable API. This issue has been patched in version 4.8.1.

Vendor: chartbrew
Product: chartbrew
Published: Mar 06, 2026
Source: NVD
CVE-2026-25887 HIGH - 7.2

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB dataset Query. This issue has been patched in version 4.8.1.

Vendor: chartbrew
Product: chartbrew
Published: Mar 06, 2026
Source: NVD
CVE-2026-29041 HIGH - 8.8

Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by improper validation of uploaded files. The application relies solely on MIME-type verification when handling file uploads and does not adequate...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 06, 2026
Source: NVD
CVE-2025-59541 HIGH - 8.1

Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects inside a course without the victim’s consent. The issue arises because sensitive actions such as project deletion do not implement anti-CSRF prot...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 06, 2026
Source: NVD
CVE-2025-55289 HIGH - 8.8

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into the platform’s social network and internal messaging features. When viewed by an authenticated user (includin...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 06, 2026
Source: NVD