Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,660
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,221 - 10,240 of 13,240 CVEs
CVE-2026-3411 HIGH - 7.3

A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /admin_single_student_update.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. T...

Vendor: angeljudesuarez
Product: university_management_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-3410 HIGH - 7.3

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/check_studid.php. Executing a manipulation of the argument student_id can lead to sql injection. The attack may be launched remotely. The exploi...

Vendor: angeljudesuarez
Product: society_management_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-3409 HIGH - 7.3

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import Endpoint. Performing a manipulation as part of File results in code injection. The attac...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3406 HIGH - 7.3

A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotely...

Vendor: projectworlds
Product: online_art_gallery_shop
Published: Mar 02, 2026
Source: NVD
CVE-2026-3400 HIGH - 8.8

A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionality of the file /goform/TextEditingConversion. The manipulation of the argument wpapsk_crypto2_4g results in stack-based buffer overflow. The attack may be launched remotely. The exp...

Vendor: tenda
Product: ac15_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2026-3399 HIGH - 8.8

A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. The manipulation of the argument dips leads to buffer overflow. The attack may be initiated remotely. The exploit is public...

Vendor: tenda
Product: f453_firmware
Published: Mar 01, 2026
Source: NVD
CVE-2026-3398 HIGH - 8.8

A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead to buffer overflow. The attack can be launched remotely. The exploit has been pub...

Vendor: tenda
Product: f453_firmware
Published: Mar 01, 2026
Source: NVD
CVE-2026-3395 HIGH - 7.3

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack re...

Vendor: max-3000
Product: maxsite_cms
Published: Mar 01, 2026
Source: NVD
CVE-2026-3380 HIGH - 8.8

A vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page results in buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

Vendor: tenda
Product: f453_firmware
Published: Mar 01, 2026
Source: NVD
CVE-2026-3379 HIGH - 8.8

A vulnerability has been found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be use...

Vendor: tenda
Product: f453_firmware
Published: Mar 01, 2026
Source: NVD
CVE-2026-3378 HIGH - 8.8

A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

Vendor: tenda
Product: f453_firmware
Published: Mar 01, 2026
Source: NVD
CVE-2026-3377 HIGH - 8.8

A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a manipulation of the argument page results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

Vendor: tenda
Product: f453_firmware
Published: Mar 01, 2026
Source: NVD
CVE-2026-3376 HIGH - 8.8

A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSafeMacFilter of the file /goform/SafeMacFilter. Such manipulation of the argument page leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been di...

Vendor: tenda
Product: f453_firmware
Published: Feb 28, 2026
Source: NVD
CVE-2026-28562 HIGH - 8.2

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers exploit the wpfob parameter with CASE WHEN payloads to perform blind boolean extraction of credentia...

Vendor: gVectors Team
Product: wpForo Forum
Published: Feb 28, 2026
Source: NVD
CVE-2025-13673 HIGH - 7.5

The Tutor LMS โ€“ eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin...

Vendor: themeum
Product: Tutor LMS โ€“ eLearning and online course solution
Published: Feb 28, 2026
Source: NVD
CVE-2026-2471 HIGH - 7.5

The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on all properties retrie...

Published: Feb 28, 2026
Source: NVD
CVE-2026-28426 HIGH - 8.7

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privilege...

Vendor: statamic
Product: cms
Published: Feb 27, 2026
Source: NVD
CVE-2026-28425 HIGH - 8.0

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full compromise of the appl...

Vendor: statamic
Product: cms
Published: Feb 27, 2026
Source: NVD
CVE-2026-28416 HIGH - 8.2

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP requests from a victim's server by hosting a malicious Gradio Space. When a victim application u...

Vendor: gradio-app
Product: gradio
Published: Feb 27, 2026
Source: NVD
CVE-2026-28414 HIGH - 7.5

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read arbitrary files from the file system. Python 3.13+ changed t...

Vendor: gradio-app
Product: gradio
Published: Feb 27, 2026
Source: NVD