Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,266
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,641 - 1,660 of 11,967 CVEs
CVE-2026-10225 HIGH - 7.3

A vulnerability was detected in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. This issue affects some unknown processing of the file login_check.php of the component Login. Performing a manipulation of the argument Username results in sql injection. T...

Vendor: raisulislamg4
Product: student_management_system_by_php
Published: Jun 01, 2026
Source: NVD
CVE-2026-48209 HIGH - 7.1

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associated with ticket actions. By injecting malicious JavaScript into man...

Vendor: OTRS AG
Product: OTRS, ((OTRS)) Community Edition
Published: Jun 01, 2026
Source: NVD
CVE-2026-20455 HIGH - 7.8

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784.

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Jun 01, 2026
Source: NVD
CVE-2026-20452 HIGH - 8.0

In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Jun 01, 2026
Source: NVD
CVE-2026-10221 HIGH - 7.3

A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be use...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 01, 2026
Source: NVD
CVE-2026-10220 HIGH - 7.3

A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and ...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 01, 2026
Source: NVD
CVE-2026-10219 HIGH - 7.3

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The...

Vendor: nextlevelbuilder
Product: GoClaw
Published: Jun 01, 2026
Source: NVD
CVE-2026-10214 HIGH - 7.3

A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit h...

Vendor: zhayujie
Product: chatgpt-on-wechat
Published: Jun 01, 2026
Source: NVD
CVE-2026-10208 HIGH - 7.3

A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be us...

Vendor: code-projects
Product: Online Hospital Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10206 HIGH - 8.8

A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of the file /dbsrv.asp. Performing a manipulation of the argument str results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. Th...

Vendor: D-Link
Product: DI-8400
Published: Jun 01, 2026
Source: NVD
CVE-2026-8796 HIGH - 8.1

Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_...

Published: May 31, 2026
Source: NVD
CVE-2026-10192 HIGH - 8.8

A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the file /bin/httpd. Such manipulation of the argument Time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be us...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10191 HIGH - 8.8

A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function cgiWifiMacFilterSet of the file /bin/httpd. This manipulation of the argument wifiMacFilterSet.macList.mac causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly discl...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10189 HIGH - 8.8

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to th...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10188 HIGH - 8.8

A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMac can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10186 HIGH - 7.3

A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit ha...

Vendor: code-projects
Product: Online Hospital Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10185 HIGH - 7.3

A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10184 HIGH - 7.3

A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been rel...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10183 HIGH - 8.8

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might ...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-49490 HIGH - 8.1

OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manip...

Vendor: OpenCATS
Product: OpenCATS
Published: May 31, 2026
Source: NVD