Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.4 HIGH
CVE-2026-20501 — MediaTek VDEC Heap Buffer Overflow

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…

mt8696_firmware mt6779 mt6781 mt6785 mt6789 mt6833 +100 more | Memory Corruption
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
5.5 MEDIUM
CVE-2026-20500 — Modem Improper Input Validation Denial of Service

In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitat…

mt6835 mt6878 mt6897 mt8676 mt8678 mt8755 +38 more | Denial of Service
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
9.3 CRITICAL
CVE-2026-16876 — NEC UNIVERGE IX-R/IX-V Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and s…

Remote | Authentication
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
5.0 MEDIUM
CVE-2026-86238 — projectworlds Online Examination System Feedback Form feedback.php cross site scripting

A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipul…

online_examination_system | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-86237 — openagents-org openagents http.py test_default_model server-side request forgery

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manip…

openagents | Remote | Server-Side Request Forgery
Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86236 — itsourcecode Sales and Inventory System pro_transac.php add sql injection

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argum…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 11, 2026
Sep 07, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-86235 — itsourcecode Sales and Inventory System pos_transac.php add sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86234 — itsourcecode Sales and Inventory System cust_transac.php add sql injection

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname re…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-86233 — itsourcecode Sales and Inventory System us_del.php sql injection

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulati…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
Showing 20 of 15429 Results