Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-3403 — PHPGurukul Student Record Management System edit-subject.php cross site scripting

A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Su…

student_record_system | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.8 MEDIUM
CVE-2026-3402 — PHPGurukul Student Record Management System edit-course.php cross site scripting

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the arg…

student_record_system | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.6 MEDIUM
CVE-2026-3401 — SourceCodester Web-based Pharmacy Product Management System session expiration

A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of th…

Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-3400 — Tenda AC15 TextEditingConversion stack-based overflow

A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionality of the file /goform/TextEditingConversion. The manipulation of the argument w…

ac15_firmware ac15 | Remote | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.0 HIGH
CVE-2026-3399 — Tenda F453 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow

A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. The manipulation of th…

f453_firmware f453 | Remote | Memory Corruption
Mar 01, 2026 Mar 03, 2026
Mar 01, 2026
Mar 03, 2026
9.0 HIGH
CVE-2026-3398 — Tenda F453 httpd AdvSetWan fromAdvSetWan buffer overflow

A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPP…

f453_firmware f453 | Remote | Memory Corruption
Mar 01, 2026 Mar 03, 2026
Mar 01, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-3395 — MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX …

maxsite_cms | Remote | Injection
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
7.8 HIGH
CVE-2026-3394 — jarikomppa soloud WAV File soloud_wav.cpp loadwav memory corruption

A vulnerability was detected in jarikomppa soloud up to 20200207. This affects the function SoLoud::Wav::loadwav of the file src/audiosource/wav/soloud_wav.cpp of the component WAV File Parser. Perfo…

soloud | Memory Corruption
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
4.8 MEDIUM
CVE-2026-3393 — jarikomppa soloud Audio File soloud_wav.cpp loadflac heap-based overflow

A security vulnerability has been detected in jarikomppa soloud up to 20200207. The impacted element is the function SoLoud::Wav::loadflac of the file src/audiosource/wav/soloud_wav.cpp of the compon…

soloud | Memory Corruption
Mar 01, 2026 Mar 02, 2026
Mar 01, 2026
Mar 02, 2026
5.5 MEDIUM
CVE-2026-3392 — FascinatedBox lily lily_emitter.c eval_tree null pointer dereference

A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the file src/lily_emitter.c. This manipulation causes null pointer dereference. The a…

lily | Memory Corruption
Mar 01, 2026 Mar 04, 2026
Mar 01, 2026
Mar 04, 2026
5.5 MEDIUM
CVE-2026-3391 — FascinatedBox lily lily_emitter.c clear_storages out-of-bounds

A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack…

lily | Memory Corruption
Mar 01, 2026 Mar 04, 2026
Mar 01, 2026
Mar 04, 2026
5.5 MEDIUM
CVE-2026-3390 — FascinatedBox lily Error Reporting lily_build_error.c patch_line_end out-of-bounds

A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. The manipulation le…

lily | Memory Corruption
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-3389 — Squirrel sqstdrex.cpp sqstd_rex_newnode null pointer dereference

A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer…

squirrel | Memory Corruption
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-3388 — Squirrel sqcompiler.cpp UnaryOP recursion

A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolle…

squirrel | Denial of Service
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-3387 — wren-lang wren wren_compiler.c getByteCountForArguments null pointer dereference

A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArguments of the file src/vm/wren_compiler.c. Such manipulation leads to null point…

wren | Memory Corruption
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
7.1 HIGH
CVE-2026-3386 — wren-lang wren wren_compiler.c emitOp out-of-bounds

A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This manipulation causes out-of-bounds read. It is possi…

wren | Memory Corruption
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
4.8 MEDIUM
CVE-2026-3385 — wren-lang wren wren_compiler.c resolveLocal recursion

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking loc…

wren | Denial of Service
Mar 01, 2026 Mar 02, 2026
Mar 01, 2026
Mar 02, 2026
5.5 MEDIUM
CVE-2026-3384 — ChaiScript chaiscript_eval.hpp Function_Push_Pop recursion

A security vulnerability has been detected in ChaiScript up to 6.1.0. This impacts the function chaiscript::eval::AST_Node_Impl::eval/chaiscript::eval::Function_Push_Pop of the file include/chaiscrip…

chaiscript | Denial of Service
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-3383 — ChaiScript boxed_number.hpp go divide by zero

A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the file include/chaiscript/dispatchkit/boxed_number.hpp. Executing a manipulation …

chaiscript | Denial of Service
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-3382 — ChaiScript boxed_number.hpp get_as memory corruption

A security flaw has been discovered in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::Boxed_Number::get_as of the file include/chaiscript/dispatchkit/boxed_number.hpp. Perfo…

chaiscript | Memory Corruption
Mar 01, 2026 Mar 05, 2026
Mar 01, 2026
Mar 05, 2026
Showing 20 of 5068 Results