Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,201 - 1,220 of 13,004 CVEs
CVE-2026-11508 MEDIUM - 6.3

A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The ex...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11507 MEDIUM - 6.3

A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/delete_leave_type.php. The manipulation of the argument leave_type results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11506 MEDIUM - 6.3

A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to t...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11505 MEDIUM - 5.0

A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a ...

Vendor: GL.iNet
Product: A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000
Published: Jun 08, 2026
Source: NVD
CVE-2026-11500 MEDIUM - 5.0

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass. It is possib...

Product: Weaviate
Published: Jun 08, 2026
Source: NVD
CVE-2026-11497 MEDIUM - 5.3

A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been d...

Vendor: D-Link
Product: DCS-5615
Published: Jun 08, 2026
Source: NVD
CVE-2026-11495 MEDIUM - 6.3

A vulnerability was detected in CodeAstro Ingredients Stock Management System 1.0. This impacts an unknown function of the file /Ingredients-Stock/add_stock.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be us...

Vendor: CodeAstro
Product: Ingredients Stock Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11494 MEDIUM - 4.3

A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and...

Vendor: TOTOLINK
Product: AC1200 T8
Published: Jun 08, 2026
Source: NVD
CVE-2026-11493 MEDIUM - 5.0

A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements. The attack is only possible within the local network. A high complexity level is...

Vendor: Tenda
Product: AC15
Published: Jun 08, 2026
Source: NVD
CVE-2026-11492 MEDIUM - 4.3

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to th...

Vendor: D-Link
Product: DIR-823G
Published: Jun 08, 2026
Source: NVD
CVE-2026-11487 MEDIUM - 5.3

A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The exp...

Product: Neovim
Published: Jun 08, 2026
Source: NVD
CVE-2026-11480 MEDIUM - 6.3

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. Impacted is an unknown function of the file beike/Admin/Routes/admin.php of the component Admin Design Builder Endpoint. Performing a manipulation of the argument settings.value results in sql injection. It i...

Vendor: Chengdu Everbrite Network Technology
Product: BeikeShop
Published: Jun 08, 2026
Source: NVD
CVE-2026-11479 MEDIUM - 4.2

A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manipulation leads to use of weak hash. The attack may be performed from remote. Attacks of this nature are highly complex. Th...

Vendor: yoanbernabeu
Product: grepai
Published: Jun 08, 2026
Source: NVD
CVE-2026-11477 MEDIUM - 4.3

A vulnerability was detected in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in open ...

Vendor: hs-web
Product: hsweb-framework
Published: Jun 08, 2026
Source: NVD
CVE-2026-11476 MEDIUM - 6.3

A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this issue is the function edit-admin of the file controllers/AdminController.php of the component Profile Update Endpoint. The manipulation of the argument is...

Vendor: Kushan2k
Product: student-management-system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11475 MEDIUM - 6.3

A weakness has been identified in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this vulnerability is the function getStatus of the file controllers/GradeController.php of the component Certificate Verification Endpoint. Executing a manipulation of th...

Vendor: Kushan2k
Product: student-management-system
Published: Jun 08, 2026
Source: NVD
CVE-2022-50953 MEDIUM - 6.2

WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing di...

Vendor: brooks24
Product: admin-word-count-column
Published: Jun 08, 2026
Source: NVD
CVE-2021-47984 MEDIUM - 6.4

WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the fieldnameDomain parameter. Attackers can inject JavaScript payloads through the plugin settings form at opt...

Vendor: WP24
Product: WP24 Domain Check
Published: Jun 08, 2026
Source: NVD
CVE-2021-47983 MEDIUM - 6.4

WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script pay...

Vendor: mra13
Product: Accept Stripe Payments
Published: Jun 08, 2026
Source: NVD
CVE-2021-47982 MEDIUM - 6.4

WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter th...

Vendor: maxfoundry
Product: WP-Paginate
Published: Jun 08, 2026
Source: NVD