Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-2180 — Tenda RX3 fast_setting_wifi_set stack-based overflow

A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation of the argument ssid_5g leads to stack-based buff…

rx3_firmware rx3 | Remote | Memory Corruption
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
7.2 HIGH
CVE-2026-2179 — PHPGurukul Hospital Management System manage-users.php sql injection

A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql inje…

Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
8.8 HIGH
CVE-2026-2178 — r-huijts xcode-mcp-server run_lldb index.ts registerXcodeTools command injection

A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the compone…

xcode_mcp_server | Remote | Injection
Feb 08, 2026 Mar 05, 2026
Feb 08, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-2177 — SourceCodester Prison Management System Login session fixiation

A vulnerability has been found in SourceCodester Prison Management System 1.0. The impacted element is an unknown function of the component Login. The manipulation leads to session fixiation. It is p…

Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
8.8 HIGH
CVE-2026-2176 — code-projects Contact Management System index.py sql injection

A security vulnerability has been detected in code-projects Contact Management System 1.0. This issue affects some unknown processing of the file index.py. Such manipulation of the argument selectedi…

contact_management_system | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
8.3 HIGH
CVE-2026-2175 — D-Link DIR-823X set_upnp sub_420618 os command injection

A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manipulation of the argument upnp_enable causes os comm…

dir-823x_firmware dir-823x | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2174 — code-projects Contact Management System CRUD Endpoint improper authentication

A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in imprope…

contact_management_system | Remote | Authentication
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2173 — code-projects Online Examination System login.php sql injection

A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/pa…

online_examination_system | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2172 — code-projects Online Application System for Admission Login Endpoint index.php sql inject…

A vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the compone…

Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2171 — code-projects Online Student Management System Login accounts.php sql injection

A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argu…

online_student_management_system | Remote | Injection
Feb 08, 2026 Feb 23, 2026
Feb 08, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-2169 — D-Link DWR-M921 formLtefotaUpgradeFibocom command injection

A vulnerability has been found in D-Link DWR-M921 1.1.50. This impacts an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command i…

dwr-m921_firmware dwr-m921 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
8.8 HIGH
CVE-2026-2168 — D-Link DWR-M921 formLtefotaUpgradeQuectel sub_419920 command injection

A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injectio…

dwr-m921_firmware dwr-m921 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
8.8 HIGH
CVE-2026-2167 — Totolink WA300 cstecgi.cgi setAPNetwork os command injection

A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Ipaddr result…

wa300_firmware wa300 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2166 — code-projects Online Reviewer System Login index.php sql injection

A security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulati…

online_reviewer_system | Remote | Injection
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2165 — detronetdip E-commerce Account Creation Endpoint add_seller.php missing authentication

A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Exe…

e-commerce | Remote | Authentication
Feb 08, 2026 Feb 19, 2026
Feb 08, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-2164 — detronetdip E-commerce addadhar.php unrestricted upload

A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/profile/addadhar.php. Performing a manipulation of t…

e-commerce | Remote | Authentication
Feb 08, 2026 Feb 19, 2026
Feb 08, 2026
Feb 19, 2026
7.2 HIGH
CVE-2026-2163 — D-Link DIR-600 ssdp.cgi command injection

A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVE…

dir-600_firmware dir-600 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
7.2 HIGH
CVE-2026-2162 — itsourcecode News Portal Project aboutus.php sql injection

A vulnerability was determined in itsourcecode News Portal Project 1.0. This affects an unknown part of the file /admin/aboutus.php. This manipulation of the argument pagetitle causes sql injection. …

news_portal_project | Remote | Injection
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2161 — itsourcecode Directory Management System forget-password.php sql injection

A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argumen…

directory_management_system | Remote | Injection
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2026-2160 — SourceCodester Simple Responsive Tourism Website Master.php cross site scripting

A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Master.php?f=save_packa…

Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
Showing 20 of 5117 Results