Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-5552 — PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This mani…

online_shopping_portal_project | Remote | Injection
Apr 05, 2026 Apr 29, 2026
Apr 05, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-5551 — itsourcecode Free Hotel Reservation System Parameter login.php sql injection

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. T…

free_hotel_reservation_system | Remote | Injection
Apr 05, 2026 Apr 29, 2026
Apr 05, 2026
Apr 29, 2026
9.0 HIGH
CVE-2026-5550 — Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The…

ac10_firmware ac10 | Remote | Memory Corruption
Apr 05, 2026 Apr 29, 2026
Apr 05, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-5549 — Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key

A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Pri…

ac10_firmware ac10 | Remote | Cryptography
Apr 05, 2026 Apr 29, 2026
Apr 05, 2026
Apr 29, 2026
9.0 HIGH
CVE-2026-5548 — Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument …

ac10_firmware ac10 | Remote | Memory Corruption
Apr 05, 2026 Apr 30, 2026
Apr 05, 2026
Apr 30, 2026
8.8 HIGH
CVE-2026-5547 — Tenda AC10 httpd formAddMacfilterRule os command injection

A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such manipulation leads to os command injection. It is poss…

ac10_firmware ac10 | Remote | Injection
Apr 05, 2026 Apr 30, 2026
Apr 05, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-5546 — Campcodes Complete Online Learning Management System Crud_model.php add_lesson unrestrict…

A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrest…

Remote | Misconfiguration
Apr 05, 2026 Apr 29, 2026
Apr 05, 2026
Apr 29, 2026
9.0 HIGH
CVE-2026-5544 — UTT HiPER 1250GW formRemoteControl stack-based overflow

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument …

Remote | Memory Corruption
Apr 05, 2026 Apr 24, 2026
Apr 05, 2026
Apr 24, 2026
Showing 20 of 5628 Results