Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-3797 — Tiandy Video Surveillance System 视频监控平台 CLS_REST_File.java uploadFile unrestricted upload

A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile of the file /src/com/tiandy/easy7/core/rest/CLS_REST_File…

Remote | Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
5.3 MEDIUM
CVE-2026-3796 — Qi-ANXIN QAX Virus Removal Mini Filter Driver QKSecureIO_Imp.sys ZwTerminateProcess acces…

A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter D…

| Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3631 — Buffer Over-read DoS Vulnerability in COMMGR2

Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.

commgr2 | Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3630 — Stack-based Buffer Overflow Vulnerability in COMMGR2

Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.

commgr2 | Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3795 — doramart DoraCMS v1.js createFileBypath path traversal

A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a manipulation results in path tr…

Remote | Path Traversal
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3794 — doramart DoraCMS Email API send improper authentication

A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper auth…

Remote | Authentication
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3793 — SourceCodester Sales and Inventory System GET Parameter sales_invoice1.php sql injection

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file sales_invoice1.php of the component GET Parameter Handler. This ma…

sales_and_inventory_system | Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3792 — SourceCodester Sales and Inventory System GET Parameter purchase_invoice.php sql injection

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchase_invoice.php of the component GET Parameter Handler. The manipulation of t…

sales_and_inventory_system | Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3791 — SourceCodester Sales and Inventory System Search dashboard.php sql injection

A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file dashboard.php of the component Search. The manipulati…

sales_and_inventory_system | Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3790 — SourceCodester Sales and Inventory System POST Parameter check_supplier_details.php sql i…

A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file check_supplier_details.php of the component POST Paramet…

sales_and_inventory_system | Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3789 — Bytedesk SpringAIGiteeRestController SpringAIGiteeRestService.java getModels server-side …

A vulnerability was detected in Bytedesk up to 1.3.9. Affected is the function getModels of the file source-code/src/main/java/com/bytedesk/ai/springai/providers/gitee/SpringAIGiteeRestService.java o…

Remote | Server-Side Request Forgery
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3788 — Bytedesk SpringAIOpenrouterRestController SpringAIOpenrouterRestService.java getModels se…

A security vulnerability has been detected in Bytedesk up to 1.3.9. This impacts the function getModels of the file source-code/src/main/java/com/bytedesk/ai/springai/providers/openrouter/SpringAIOpe…

Remote | Server-Side Request Forgery
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70039 — Linagora Twake OS Command Injection

An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.

| Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70034 — MSCDEX SSH2 Regular Expression Complexity Vulnerability

An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.

| Denial of Service
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70038 — Linagora Twake Cross-Site Scripting (XSS)

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrary code.

| Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.3 HIGH
CVE-2026-3787 — UltraVNC Windows Service cryptbase.dll uncontrolled search path

A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase.dll of the component Windows Service. This manipulation causes uncontrolled se…

ultravnc | Misconfiguration
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3786 — EasyCMS Request Parameter RbacuserAction.class.php sql injection

A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAction.class.php of the component Request Parameter Handler. The manipulatio…

easycms | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3785 — EasyCMS Request Parameter RbacnodeAction.class.php sql injection

A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAction.class.php of the component Request Parameter Handler. The manipulation of …

easycms | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3771 — SourceCodester/janobe Resort Reservation System accomodation.php sql injection

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads…

resort_reservation_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3770 — SourceCodester Computer Laboratory Management System cross-site request forgery

A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carr…

computer_laboratory_management_system | Remote | Cross-Site Request Forgery
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
Showing 20 of 5029 Results