Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
Showing 1,101 - 1,120 of 1,476 CVEs

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 03, 2026
Source: NVD

An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may a...

Vendor: nokia
Product: impact_mobile
Published: Mar 03, 2026
Source: NVD

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_service.php.

Vendor: oretnom23
Product: simple_online_men\'s_salon_management_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_service.

Vendor: oretnom23
Product: simple_online_men\'s_salon_management_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view_appointment.php.

Vendor: oretnom23
Product: simple_online_men\'s_salon_management_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=delete_appointment.

Vendor: oretnom23
Product: simple_online_men\'s_salon_management_system
Published: Mar 03, 2026
Source: NVD
CVE-2026-3465 LOW - 3.1

A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack is possible. The comp...

Published: Mar 03, 2026
Source: NVD

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread'...

Vendor: djangoproject
Product: Django
Published: Mar 03, 2026
Source: NVD
CVE-2026-3463 LOW - 3.3

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document Parser. This manipulation causes heap-based buffer overflow. The attack can only be executed locally...

Published: Mar 03, 2026
Source: NVD

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiat...

Vendor: Dataease
Product: SQLBot
Published: Mar 03, 2026
Source: NVD
CVE-2026-3449 LOW - 3.3

Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This ...

Published: Mar 03, 2026
Source: NVD

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL...

Vendor: Gallagher
Product: Command Centre Server
Published: Mar 03, 2026
Source: NVD

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.

Vendor: nocodb
Product: nocodb
Published: Mar 02, 2026
Source: NVD

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched in version 0.301.3.

Vendor: nocodb
Product: nocodb
Published: Mar 02, 2026
Source: NVD
CVE-2026-0995 LOW - 3.6

An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesses related to SME.

Published: Mar 02, 2026
Source: NVD
CVE-2026-3407 LOW - 3.3

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has bee...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3405 LOW - 3.1

A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitabi...

Vendor: jeesite
Product: jeesite
Published: Mar 02, 2026
Source: NVD
CVE-2026-3403 LOW - 2.4

A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The explo...

Vendor: phpgurukul
Product: student_record_system
Published: Mar 02, 2026
Source: NVD