Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,270
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,601 - 1,620 of 11,967 CVEs
CVE-2026-42683 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: Jun 01, 2026
Source: NVD
CVE-2026-42681 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.

Vendor: E2Pdf.com
Product: e2pdf
Published: Jun 01, 2026
Source: NVD
CVE-2026-37221 HIGH - 7.5

FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pending event. The near-RT RIC uses assert() to enforce the existence of a pending event during response processing. A remote unauthenticated attacker can send a forged RIC_SUBSCRIPTION...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37220 HIGH - 7.5

FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a mapping between SCTP association and E2 node always exists in the cleanup path and enforces this via assert(). A remote unauthenticated attacker can crash the near-RT RIC (port 364...

Published: Jun 01, 2026
Source: NVD
CVE-2026-10263 HIGH - 7.3

A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made p...

Vendor: SourceCodester
Product: Computer Repair Shop Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10262 HIGH - 7.3

A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the p...

Vendor: code-projects
Product: Real State Services
Published: Jun 01, 2026
Source: NVD
CVE-2026-10261 HIGH - 7.3

A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

Vendor: CodeAstro
Product: Online Job Portal
Published: Jun 01, 2026
Source: NVD
CVE-2026-10260 HIGH - 7.3

A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now publi...

Vendor: CodeAstro
Product: Online Job Portal
Published: Jun 01, 2026
Source: NVD
CVE-2026-10259 HIGH - 8.8

A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been ...

Vendor: H3C
Product: Magic B0
Published: Jun 01, 2026
Source: NVD
CVE-2024-40646 HIGH - 8.6

Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to commit fbde301b97986d5913fc4bc95f5445750d282e11 are vulnerable to path traversal. Users should upgrade to a version containing commit fbde301b97986d5913fc4bc95f5445750d282e11 to rece...

Vendor: vertex-app
Product: vertex
Published: Jun 01, 2026
Source: NVD
CVE-2026-47412 HIGH - 8.1

praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47415 HIGH - 8.3

praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47417 HIGH - 8.1

praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47418 HIGH - 8.1

praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47423 HIGH - 8.2

DOMPurify XSS via selectedcontent re-clone

Vendor: npm
Product: dompurify
Published: Jun 01, 2026
Source: GitHub
CVE-2026-48119 HIGH - 7.1

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has been patched in version 2.0.12.

Vendor: go
Product: github.com/nezhahq/nezha
Published: Jun 01, 2026
Source: GitHub
CVE-2026-10253 HIGH - 7.3

A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

Vendor: itsourcecode
Product: Online House Rental System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10252 HIGH - 7.3

A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publi...

Vendor: itsourcecode
Product: Online House Rental System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10251 HIGH - 7.3

A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been ma...

Vendor: itsourcecode
Product: Online House Rental System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10250 HIGH - 7.3

A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely...

Vendor: itsourcecode
Product: Online Blood Bank Management System
Published: Jun 01, 2026
Source: NVD