Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,746
Quick preset (or use dates below)
Clear Filters
Showing 1,641 - 1,660 of 12,883 CVEs
CVE-2023-54350 HIGH - 7.5

WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create m...

Vendor: webandprint
Product: Augmented Reality
Published: Jun 08, 2026
Source: NVD
CVE-2026-11474 HIGH - 7.3

A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown function of the file service/RegisterService.php of the component Registration Endpoint. Performing a manipulation of the argument stimg results in unrestr...

Vendor: Kushan2k
Product: student-management-system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11472 HIGH - 7.3

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /index1.php. This manipulation of the argument Password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be ...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11471 HIGH - 7.3

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /index2.php. The manipulation of the argument Password results in sql injection. It is possible to launch the attack remotely. The exploit has been made public a...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11463 HIGH - 7.3

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a manipulation can lead to type confusion. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was...

Vendor: USCiLab
Product: Cereal
Published: Jun 07, 2026
Source: NVD
CVE-2026-11462 HIGH - 7.3

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorizati...

Vendor: Chengdu Everbrite Network Technology
Product: BeikeShop
Published: Jun 07, 2026
Source: NVD
CVE-2026-11460 HIGH - 7.3

A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has been published and may be used. The maintainer was notified o...

Vendor: Boost
Product: Serialization
Published: Jun 07, 2026
Source: NVD
CVE-2026-49494 HIGH - 7.5

Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length value (taken from the IPv6 fixed header's payload length field) by the size of each IPv6 extension header without validati...

Vendor: Comodo
Product: Comodo Internet Security
Published: Jun 07, 2026
Source: NVD
CVE-2026-11457 HIGH - 7.3

A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the component JimuReport test-connection Endpoint. Performing a manipulation of the argument dbType/dbDri...

Vendor: erzhongxmu
Product: JeeWMS
Published: Jun 07, 2026
Source: NVD
CVE-2026-11456 HIGH - 7.3

A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php of the component HTTP GET Request Handler. Such manipulation of the argument gblOrgID leads to sql injection. The attack may be launched remotely. The exploit is publicly availabl...

Vendor: Chanjet
Product: CRM
Published: Jun 07, 2026
Source: NVD
CVE-2026-11452 HIGH - 7.3

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-bin/glc of the component SET_USER_PWD Handler. The manipulation of the argument Password leads to command injection. The attack can be initiated remotely. Upgrading to version 4.8....

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 07, 2026
Source: NVD
CVE-2026-11451 HIGH - 7.3

A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulation of the argument media_dir can lead to command injection. It is possible to launch the attack remotely. Upgrading to version 4....

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 07, 2026
Source: NVD
CVE-2026-11450 HIGH - 7.3

A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler. Performing a manipulation of the argument dev_name results in command injection. It is possible to initiate the attack remotel...

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 07, 2026
Source: NVD
CVE-2026-26422 HIGH - 8.4

clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.

Vendor: Clash Verge Rev
Product: clash-verge-service-ipc
Published: Jun 06, 2026
Source: NVD
CVE-2026-11437 HIGH - 7.3

A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publi...

Vendor: perfree
Product: go-fastdfs-web
Published: Jun 06, 2026
Source: NVD
CVE-2026-11435 HIGH - 7.3

A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor wa...

Vendor: Jinher
Product: OA
Published: Jun 06, 2026
Source: NVD
CVE-2026-11413 HIGH - 8.8

A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the file /sbin/jdcweb_rpc. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclos...

Vendor: JingDong
Product: JD Cloud Box AX6600
Published: Jun 06, 2026
Source: NVD
CVE-2026-10725 HIGH - 7.5

Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the "HTTP/2 bomb"). The headers_decode method materialises a full key+val...

Vendor: CRUX
Product: Protocol::HTTP2
Published: Jun 06, 2026
Source: NVD
CVE-2026-9851 HIGH - 7.2

The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a non...

Published: Jun 06, 2026
Source: NVD
CVE-2026-7537 HIGH - 7.2

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for aut...

Published: Jun 06, 2026
Source: NVD