Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-20002 — "Cisco Secure FMC Software SQL Injection Vulnerability"

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulner…

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.5 MEDIUM
CVE-2026-20001 — Cisco Secure Firewall Management Center Software SQL Injection Vulnerabilities

A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inad…

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-70220 — D-Link DIR-513 Stack Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4.

dir-513_firmware dir-513 | Remote | Memory Corruption
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2025-70218 — D-Link DIR-513 Stack Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.

dir-513_firmware dir-513 | Remote | Memory Corruption
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
8.8 HIGH
CVE-2019-25507 — Ashop Shopping Cart Software Lastest SQL Injection via index.php

Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'shop' parameter. Attackers…

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.8 HIGH
CVE-2019-25506 — FreeSMS 2.1.2 Authentication Bypass via SQL Injection

FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass authentication by injecting SQL code through the log…

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.1 HIGH
CVE-2019-25505 — Tradebox 5.4 SQL Injection via symbol Parameter

Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the symbol parameter. Attackers can send POST req…

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.8 HIGH
CVE-2019-25504 — NCrypted Jobgator Lastest SQL Injection via agents Find-Jobs

NCrypted Jobgator contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the experience parameter. Attackers can se…

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.1 HIGH
CVE-2019-25503 — PHPads 2.0 SQL Injection via click.php3 bannerID

PHPads 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the bannerID parameter in click.php3. Att…

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2019-25502 — Simple Job Script Cross-Site Scripting via job_type_value Parameter

Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. At…

simplejobscript | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.8 HIGH
CVE-2019-25501 — Simple Job Script SQL Injection via delete_application_ajax.php

Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the app_id parameter. Attackers can send POST re…

simplejobscript | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.8 HIGH
CVE-2019-25500 — Simple Job Script SQL Injection via register-recruiters endpoint

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the employerid parameter. Attackers can se…

simplejobscript | Remote | Injection
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2019-25499 — Simple Job Script SQL Injection via get_job_applications_ajax.php

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send P…

simplejobscript | Remote | Injection
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
8.8 HIGH
CVE-2019-25498 — Simple Job Script SQL Injection via searched Endpoint

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers …

simplejobscript | Remote | Injection
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
8.7 HIGH
CVE-2026-3520 — Multer vulnerable to Denial of Service via uncontrolled recursion

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed reques…

| Denial of Service
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.9 MEDIUM
CVE-2026-29069 — Craft has an unauthenticated activation email trigger with potential user enumeration

Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission …

craft_cms | Remote | Authentication
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.6 HIGH
CVE-2026-28784 — Craft is affected by potential authenticated Remote Code Execution via Twig SSTI

Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in …

craft_cms | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
9.4 CRITICAL
CVE-2026-28783 — Craft has a Twig Function Blocklist Bypass

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Clo…

craft_cms | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-28782 — Craft has a Permission Bypass and IDOR in Duplicate Entry Action

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission to perform this action on the spe…

craft_cms | Remote | Authorization
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.1 HIGH
CVE-2026-28781 — Craft Affected by Entries Authorship Spoofing via Mass Assignment

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" perm…

craft_cms | Remote | Authorization
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
Showing 20 of 5091 Results