Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-2939 — itsourcecode Student Management System Add Student add_student cross site scripting

A vulnerability was found in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /add_student/ of the component Add Student Module. The manipulation re…

school_management_system student_management_system | Remote | Cross-Site Scripting
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
7.5 HIGH
CVE-2026-2938 — SourceCodester Student Result Management System update_smtp.php access control

A vulnerability has been found in SourceCodester Student Result Management System 1.0. The affected element is an unknown function of the file /srms/script/admin/core/update_smtp.php. The manipulatio…

Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
8.3 HIGH
CVE-2026-2935 — UTT HiPER 810G ConfigExceptMSN strcpy buffer overflow

A weakness has been identified in UTT HiPER 810G up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/ConfigExceptMSN. Executing a manipulation of the argument remark can le…

810g_firmware 810g | Remote | Memory Corruption
Feb 22, 2026 Feb 24, 2026
Feb 22, 2026
Feb 24, 2026
4.8 MEDIUM
CVE-2026-2934 — YiFang CMS Extended Management D_friendLinkGroup.php update cross site scripting

A security vulnerability has been detected in YiFang CMS up to 2.0.5. This impacts the function update of the file app/db/admin/D_friendLinkGroup.php of the component Extended Management Module. The …

yifang yifang | Remote | Cross-Site Scripting
Feb 22, 2026 Feb 24, 2026
Feb 22, 2026
Feb 24, 2026
5.3 MEDIUM
CVE-2026-2385 — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu,…

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all v…

Remote | Cryptography
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
4.8 MEDIUM
CVE-2026-2933 — YiFang CMS Extended Management D_adManage.php update cross site scripting

A weakness has been identified in YiFang CMS up to 2.0.5. This affects the function update of the file app/db/admin/D_adManage.php of the component Extended Management Module. Executing a manipulatio…

yifang yifang | Remote | Cross-Site Scripting
Feb 22, 2026 Feb 24, 2026
Feb 22, 2026
Feb 24, 2026
4.8 MEDIUM
CVE-2026-2932 — YiFang CMS Extended Management D_adPosition.php update cross site scripting

A security flaw has been discovered in YiFang CMS up to 2.0.5. The impacted element is the function update of the file app/db/admin/D_adPosition.php of the component Extended Management Module. Perfo…

yifang yifang | Remote | Cross-Site Scripting
Feb 22, 2026 Feb 24, 2026
Feb 22, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2930 — Tenda A18 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflow

A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Such manipulation of t…

a18_firmware a18 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2929 — D-Link DWR-M960 Wireless Access Control Endpoint formWlAc sub_453140 stack-based overflow

A vulnerability was determined in D-Link DWR-M960 1.01.07. Impacted is the function sub_453140 of the file /boafrm/formWlAc of the component Wireless Access Control Endpoint. This manipulation of the…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
4.3 MEDIUM
CVE-2026-1369 — Conditional CAPTCHA <= 4.0.0 - Open Redirect

The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

Remote | Misconfiguration
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2928 — D-Link DWR-M960 WLAN Encryption Configuration Endpoint formWlEncrypt sub_452CCC stack-bas…

A vulnerability was found in D-Link DWR-M960 1.01.07. This issue affects the function sub_452CCC of the file /boafrm/formWlEncrypt of the component WLAN Encryption Configuration Endpoint. The manipul…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2927 — D-Link DWR-M960 Operation Mode Configuration Endpoint formOpMode sub_462590 stack-based o…

A vulnerability has been found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_462590 of the file /boafrm/formOpMode of the component Operation Mode Configuration Endpoint. Th…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2926 — D-Link DWR-M960 LTE Configuration Endpoint formLteSetup sub_4237AC stack-based overflow

A flaw has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4237AC of the file /boafrm/formLteSetup of the component LTE Configuration Endpoint. Executing a manipulation of the ar…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2925 — D-Link DWR-M960 Bridge VLAN Configuration Endpoint formBridgeVlan sub_42B5A0 stack-based …

A vulnerability was detected in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_42B5A0 of the file /boafrm/formBridgeVlan of the component Bridge VLAN Configuration Endpoint. Perf…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
7.0 HIGH
CVE-2026-2913 — libvips source.c vips_source_read_to_memory heap-based overflow

A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffe…

libvips | Memory Corruption
Feb 22, 2026 Feb 24, 2026
Feb 22, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-2912 — code-projects Online Reviewer System studentresult-view.php sql injection

A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation…

online_reviewer_system | Remote | Injection
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2911 — Tenda FH451 GstDhcpSetSer buffer overflow

A vulnerability has been found in Tenda FH451 up to 1.0.0.9. This issue affects some unknown processing of the file /goform/GstDhcpSetSer. The manipulation leads to buffer overflow. It is possible to…

fh451_firmware fh451 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2910 — Tenda HG9 formPing6 stack-based overflow

A flaw has been found in Tenda HG9 300001138. This vulnerability affects unknown code of the file /boaform/formPing6. Executing a manipulation of the argument pingAddr can lead to stack-based buffer …

hg9_firmware hg9 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2909 — Tenda HG9 Diagnostic Ping Endpoint formPing stack-based overflow

A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Performing a manipulation of the argument pi…

hg9_firmware hg9 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2908 — Tenda HG9 Loopback Detection Configuration Endpoint formLoopBack stack-based overflow

A security vulnerability has been detected in Tenda HG9 300001138. Affected by this issue is some unknown functionality of the file /boaform/formLoopBack of the component Loopback Detection Configura…

hg9_firmware hg9 | Remote | Memory Corruption
Feb 22, 2026 Feb 23, 2026
Feb 22, 2026
Feb 23, 2026
Showing 20 of 5265 Results