Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,640
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,541 - 10,560 of 13,241 CVEs
CVE-2026-2961 HIGH - 8.8

A vulnerability has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4196C4 of the file /boafrm/formVpnConfigSetup of the component VPN Configuration Endpoint. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack is possible to be carried o...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2026-2960 HIGH - 8.8

A flaw has been found in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_468D64 of the file /boafrm/formDhcpv6s. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and ma...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2026-2959 HIGH - 8.8

A vulnerability was detected in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_44E0F8 of the file /boafrm/formNewSchedule. Performing a manipulation of the argument url results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is ...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2026-2958 HIGH - 8.8

A security vulnerability has been detected in D-Link DWR-M960 1.01.07. Affected is the function sub_457C5C of the file /boafrm/formWsc. Such manipulation of the argument save_apply leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and ...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2019-25462 HIGH - 8.2

Web Ofisi Rent a Car v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'klima' parameter. Attackers can send GET requests to with malicious 'klima' values to extract sensitive database...

Vendor: Web-ofisi
Product: Rent a Car
Published: Feb 22, 2026
Source: NVD
CVE-2019-25461 HIGH - 8.2

Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter. Attackers can send POST requests to the ajax/productsFilterSearch endpoint with malicious 'q�...

Vendor: Web-ofisi
Product: Ticaret
Published: Feb 22, 2026
Source: NVD
CVE-2019-25460 HIGH - 8.2

Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter. Attackers can send requests to the arama endpoint with malicious 'q' values using time...

Vendor: Web-ofisi
Product: Ticaret
Published: Feb 22, 2026
Source: NVD
CVE-2019-25459 HIGH - 8.2

Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into parameters like emlak_durumu, emlak_tipi, il, ilce, kelime, and semt to extract sensitive ...

Vendor: Web-ofisi
Product: Emlak
Published: Feb 22, 2026
Source: NVD
CVE-2019-25458 HIGH - 8.2

Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can send requests to with malicious payloads in the 'il', 'kat', or 'kelime' p...

Vendor: Web-ofisi
Product: Firma Rehberi
Published: Feb 22, 2026
Source: NVD
CVE-2019-25457 HIGH - 8.2

Web Ofisi Firma v13 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'oz' array parameter. Attackers can send GET requests to category pages with malicious 'oz[]' values using time-based...

Vendor: Web-ofisi
Product: Firma
Published: Feb 22, 2026
Source: NVD
CVE-2019-25456 HIGH - 8.2

Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database informa...

Vendor: Web-ofisi
Product: Emlak
Published: Feb 22, 2026
Source: NVD
CVE-2019-25455 HIGH - 8.2

Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'a' parameter. Attackers can send GET requests to with malicious 'a' parameter values to extract sensitive databas...

Vendor: Web-ofisi
Product: Ticaret
Published: Feb 22, 2026
Source: NVD
CVE-2026-2952 HIGH - 7.3

A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request Handler. This manipulation of the argument xajaxargs causes os command injection. The attack is possible to be carried out remotely. The exploit has be...

Vendor: vaelsys
Product: vaelsys
Published: Feb 22, 2026
Source: NVD
CVE-2019-25452 HIGH - 8.2

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious SQL payloads in the elemid parameter to extract s...

Vendor: Dolibarr
Product: Dolibarr ERP/CRM
Published: Feb 22, 2026
Source: NVD
CVE-2019-25450 HIGH - 7.1

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in car...

Vendor: Dolibarr
Product: Dolibarr ERP/CRM
Published: Feb 22, 2026
Source: NVD
CVE-2019-25446 HIGH - 8.2

DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters. Attackers can send POST requests to /korisnikinfo.php with malicious SQL syntax in these parameter...

Vendor: Digit-Rs
Product: DIGIT CENTRIS
Published: Feb 22, 2026
Source: NVD
CVE-2019-25443 HIGH - 8.2

Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can supply malicious SQL payloads in the name, description, quantity, or cat_id parameters to add-item.php to execute ...

Vendor: edlangley
Product: inventory-webapp
Published: Feb 22, 2026
Source: NVD
CVE-2019-25442 HIGH - 8.2

Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the PF parameter. Attackers can send GET requests to member_profile.asp with malicious PF values to extract sensitive database information.

Vendor: Webwiz
Product: Web Wiz Forums
Published: Feb 22, 2026
Source: NVD
CVE-2019-25440 HIGH - 8.2

WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the prod_id parameter. Attackers can send GET requests to product_detail.php with malicious prod_id values to extract sensitive database informatio...

Vendor: Webincorp
Product: WebIncorp ERP
Published: Feb 22, 2026
Source: NVD
CVE-2019-25439 HIGH - 8.2

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive databa...

Vendor: Novismart
Product: NoviSmart CMS
Published: Feb 22, 2026
Source: NVD