Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,181 - 1,200 of 13,004 CVEs
CVE-2026-11529 MEDIUM - 6.3

A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the ...

Vendor: designcomputer
Product: mysql-mcp-server
Published: Jun 08, 2026
Source: NVD
CVE-2020-37248 MEDIUM - 6.5

OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.

Vendor: OfflineIMAP
Product: OfflineIMAP
Published: Jun 08, 2026
Source: NVD
CVE-2026-25558 MEDIUM - 4.8

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through ...

Vendor: QloApps
Product: QloApps
Published: Jun 08, 2026
Source: NVD
CVE-2026-11521 MEDIUM - 6.3

A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controller/TransactionController.java of the component Transaction En...

Vendor: Mohammed-eid35
Product: bank-management-system-springboot
Published: Jun 08, 2026
Source: NVD
CVE-2026-11519 MEDIUM - 6.3

A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the component Account Creation Handler. The manipulation of the argument ROLE results in improper authorizati...

Vendor: SourceCodester
Product: Inventory System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11518 MEDIUM - 4.3

A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The manipulation of the argument fullname/username leads to cross site scripting. The attack is possible to be carried out remotely. Th...

Vendor: SourceCodester
Product: Inventory System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11516 MEDIUM - 5.5

A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBinds results in buffer overflow. The exploit has been made public and could be used.

Vendor: UTT
Product: HiPER 2610G
Published: Jun 08, 2026
Source: NVD
CVE-2026-9549 MEDIUM - 4.8

Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser ...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-8833 MEDIUM - 5.4

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting whe...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-8078 MEDIUM - 4.8

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-7765 MEDIUM - 5.3

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's pers...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-7186 MEDIUM - 5.4

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when ...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-11515 MEDIUM - 5.3

A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input passw...

Vendor: SourceCodester
Product: Barangay Resident Profiling and Information Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11514 MEDIUM - 6.3

A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11513 MEDIUM - 6.3

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11512 MEDIUM - 4.3

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclos...

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-3011 MEDIUM - 6.4

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' met...

Published: Jun 08, 2026
Source: NVD
CVE-2026-11569 MEDIUM - 5.4

A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored cross-site scripting when ...

Vendor: Red Hat
Product: Red Hat Quay 3
Published: Jun 08, 2026
Source: NVD
CVE-2026-11510 MEDIUM - 6.3

A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection. It is possible to initiate the attack remotely. The exploit has been released...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11509 MEDIUM - 6.3

A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote.

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD