Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-2164 — detronetdip E-commerce addadhar.php unrestricted upload

A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/profile/addadhar.php. Performing a manipulation of t…

e-commerce | Remote | Authentication
Feb 08, 2026 Feb 19, 2026
Feb 08, 2026
Feb 19, 2026
7.2 HIGH
CVE-2026-2163 — D-Link DIR-600 ssdp.cgi command injection

A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVE…

dir-600_firmware dir-600 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
7.2 HIGH
CVE-2026-2162 — itsourcecode News Portal Project aboutus.php sql injection

A vulnerability was determined in itsourcecode News Portal Project 1.0. This affects an unknown part of the file /admin/aboutus.php. This manipulation of the argument pagetitle causes sql injection. …

news_portal_project | Remote | Injection
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2161 — itsourcecode Directory Management System forget-password.php sql injection

A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argumen…

directory_management_system | Remote | Injection
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2026-2160 — SourceCodester Simple Responsive Tourism Website Master.php cross site scripting

A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Master.php?f=save_packa…

Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2026-2159 — SourceCodester Simple Responsive Tourism Website Registration Master.php cross site scrip…

A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Execut…

Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2158 — code-projects Student Web Portal check_user.php sql injection

A vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql i…

student_web_portal | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
8.3 HIGH
CVE-2026-2157 — D-Link DIR-823X set_static_route_table sub_4175CC os command injection

A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table. Such manipulation of the argument interface/dest…

dir-823x_firmware dir-823x | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
4.8 MEDIUM
CVE-2026-2156 — code-projects Online Student Management System Announcement Management index.php cross si…

A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown function of the file /admin/announcement/index.php?view=add of the component A…

online_student_management_system | Remote | Cross-Site Scripting
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
8.3 HIGH
CVE-2026-2155 — D-Link DIR-823X Configuration set_dmz sub_4208A0 os command injection

A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of …

dir-823x_firmware dir-823x | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
6.1 MEDIUM
CVE-2026-2154 — SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System Patient Regist…

A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impacted is an unknown function of the file /registration.php of the component Patien…

patients_waiting_area_queue_management_system | Remote | Cross-Site Scripting
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2026-2153 — mwielgoszewski doorman views.py is_safe_url redirect

A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can l…

doorman | Remote | Server-Side Request Forgery
Feb 08, 2026 Mar 05, 2026
Feb 08, 2026
Mar 05, 2026
8.3 HIGH
CVE-2026-2152 — D-Link DIR-615 Web Configuration adv_routing.php os command injection

A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the ar…

dir-615_firmware dir-615 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
8.3 HIGH
CVE-2026-2151 — D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection

A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr  leads…

dir-615_firmware dir-615 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
6.1 MEDIUM
CVE-2026-2150 — SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System checkin.php cr…

A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /checkin.php. This manipulati…

patients_waiting_area_queue_management_system | Remote | Cross-Site Scripting
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2026-2149 — SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System appointments.p…

A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /appointments.ph…

patients_waiting_area_queue_management_system | Remote | Cross-Site Scripting
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
7.5 HIGH
CVE-2026-2148 — Tenda AC21 Web Management DownloadFlash information disclosure

A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the component Web Management Interface. The manipulation le…

ac21_firmware ac21 | Remote | Information Disclosure
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2026-2147 — Tenda AC21 Web Management DownloadLog information disclosure

A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Management Interface. Executing a manipulation can lea…

ac21_firmware ac21 | Remote | Information Disclosure
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
8.8 HIGH
CVE-2026-2146 — guchengwuyue yshopmall co.yixiang.utils.FileUtil updateAvatar unrestricted upload

A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Perfo…

yshopmall | Remote | Misconfiguration
Feb 08, 2026 Feb 17, 2026
Feb 08, 2026
Feb 17, 2026
5.4 MEDIUM
CVE-2026-2145 — cym1102 nginxWebUI Web Management check cross site scripting

A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of the component Web Management Interface. Such manipul…

nginxwebui | Remote | Cross-Site Scripting
Feb 08, 2026 Mar 05, 2026
Feb 08, 2026
Mar 05, 2026
Showing 20 of 5089 Results