Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
Showing 1,641 - 1,660 of 3,569 CVEs
CVE-2026-33698 CRITICAL - 9.8

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals wit...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 10, 2026
Source: NVD
CVE-2026-32892 CRITICAL - 9.1

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshe...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 10, 2026
Source: NVD

PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without validating archive member paths. A .praison bundle containing ../../ entries will write files outside the intended output directory. An attacker who ...

Vendor: MervinPraison
Product: PraisonAI
Published: Apr 10, 2026
Source: NVD
CVE-2026-23781 CRITICAL - 9.8

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow unauthorized access to the MFT API debug interface.

Published: Apr 10, 2026
Source: NVD
CVE-2026-36236 CRITICAL - 9.8

SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.

Vendor: janobe
Product: engineers_online_portal
Published: Apr 10, 2026
Source: NVD
CVE-2026-36235 CRITICAL - 9.8

A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation.

Vendor: itsourcecode
Product: online_student_enrollment_system
Published: Apr 10, 2026
Source: NVD
CVE-2026-36234 CRITICAL - 9.8

itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.

Vendor: itsourcecode
Product: online_student_enrollment_system
Published: Apr 10, 2026
Source: NVD
CVE-2026-36233 CRITICAL - 9.8

A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for...

Vendor: itsourcecode
Product: online_student_enrollment_system
Published: Apr 10, 2026
Source: NVD
CVE-2026-36232 CRITICAL - 9.8

A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or...

Vendor: itsourcecode
Product: online_student_enrollment_system
Published: Apr 10, 2026
Source: NVD
CVE-2026-29861 CRITICAL - 9.8

PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.

Published: Apr 10, 2026
Source: NVD
CVE-2025-44560 CRITICAL - 9.8

owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.

Published: Apr 10, 2026
Source: NVD
CVE-2026-5412 CRITICAL - 9.9

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issu...

Vendor: go
Product: github.com/juju/juju
Published: Apr 10, 2026
Source: NVD
CVE-2026-6057 CRITICAL - 9.8

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

Published: Apr 10, 2026
Source: NVD
CVE-2026-6029 CRITICAL - 9.8

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument User results in os command injection. The attack may be launched remotely. The ...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6028 CRITICAL - 9.8

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable leads to os command injection. The attack may be initiated remotely. T...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6027 CRITICAL - 9.8

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead to os command injection. The attack can be launched remot...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6026 CRITICAL - 9.8

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument enable results in os command injection. The attack can be...

Published: Apr 10, 2026
Source: NVD
CVE-2026-1115 CRITICAL - 9.6

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backend/routers/social/__init__.py`, where user-provided content is directly assigned...

Vendor: lollms
Product: lollms
Published: Apr 10, 2026
Source: NVD
CVE-2026-6025 CRITICAL - 9.8

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack remotely. The exp...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5997 CRITICAL - 9.8

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass results in os command injection. It is possible to launch the attack...

Published: Apr 10, 2026
Source: NVD