Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-9451 — code-projects Employee Management System applyleaveprocess.php sql injection

A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulatio…

employee_management_system | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9450 — code-projects Employee Management System psubmit.php sql injection

A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql inje…

employee_management_system | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9449 — code-projects Employee Management System changepassemp.php sql injection

A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possibl…

employee_management_system | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9448 — code-projects Employee Management System applyleave.php cross site scripting

A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the file /applyleave.php. Executing a manipulation of the argument ID can lead to c…

employee_management_system | Remote | Cross-Site Scripting
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9447 — SourceCodester Simple POS and Inventory System search.php sql injection

A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Na…

simple_pos_and_inventory_system | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
5.3 MEDIUM
CVE-2026-46745 — Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reach…

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache…

apache-airflow-providers-fab | Remote | Injection
May 25, 2026 May 27, 2026
May 25, 2026
May 27, 2026
5.3 MEDIUM
CVE-2026-40127 — Authorization Bypass Through User-Controlled Key in OutSystems Lifetime

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions perf…

Remote | Authorization
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
5.8 MEDIUM
CVE-2026-9446 — SourceCodester Simple POS and Inventory System edit_customer.php sql injection

A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argume…

simple_pos_and_inventory_system | Remote | Injection
May 25, 2026 May 28, 2026
May 25, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-9445 — SourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted…

A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulati…

simple_pos_and_inventory_system | Remote | Misconfiguration
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
5.8 MEDIUM
CVE-2026-9444 — SourceCodester Simple POS and Inventory System GET Parameter deleteproduct.php delete sql…

A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler.…

simple_pos_and_inventory_system | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9443 — Edimax BR-6478AC POST Request formL2TPSetup buffer overflow

A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The…

br-6478ac_firmware | Remote | Memory Corruption
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9442 — Edimax BR-6478AC POST Request formiNICSiteSurvey buffer overflow

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipul…

br-6478ac_firmware | Remote | Memory Corruption
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9441 — Edimax BR-6478AC POST Request formiNICbasic command injection

A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing …

br-6478ac_firmware | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
5.2 MEDIUM
CVE-2026-9274 — Information Exposure Vulnerability in CP-Plus Wi-Fi Camera

This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing…

| Information Disclosure
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-5223 — Crates in third party registries can override the cached source of other crates

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The…

cargo | Remote | Supply Chain
May 25, 2026 Jun 01, 2026
May 25, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-5222 — Cargo can be coerced to share credentials between registries

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary na…

cargo rust | Remote | Misconfiguration
May 25, 2026 Jun 01, 2026
May 25, 2026
Jun 01, 2026
8.1 HIGH
CVE-2026-45361 — Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHoo…

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attac…

apache-airflow-providers-google | Remote | Misconfiguration
May 25, 2026 Jun 01, 2026
May 25, 2026
Jun 01, 2026
6.8 MEDIUM
CVE-2026-9490 — Acer Care Center creates a Named Pipe with a weak Security Descriptor

A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user t…

care_center | Denial of Service
May 25, 2026 Jun 04, 2026
May 25, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-9440 — Edimax BR-6478AC POST Request formAccept command injection

A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulat…

br-6478ac_firmware | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9439 — Edimax BR-6675nD stainfo command injection

A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command injection. It is poss…

br-6675nd | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
Showing 20 of 6714 Results