Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2015-20115 — RealtyScript 4.0.2 Stored Cross-Site Scripting via File Upload Parameter

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload …

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.1 MEDIUM
CVE-2015-20114 — RealtyScript 4.0.2 Cross-Site Scripting via Multiple Parameters

Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious input through multiple para…

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.9 MEDIUM
CVE-2015-20113 — RealtyScript 4.0.2 Multiple Cross-Site Request Forgery and Persistent Cross-Site Scriptin…

Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malici…

Remote | Cross-Site Request Forgery
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
8.7 HIGH
CVE-2013-20006 — Qool CMS Multiple Persistent Cross-Site Scripting Vulnerabilities

Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being stored and returned to users…

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.9 MEDIUM
CVE-2013-20005 — Qool CMS 2.0 RC2 Cross-Site Request Forgery via adduser

Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious web pages. Attackers c…

Remote | Cross-Site Request Forgery
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4185 — GPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflow

A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_def_bits_jpeg of the file src/scene_manager/swf_parse.c of the component MP4Box.…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4184 — D-Link DIR-816 goahead form2Wl5BasicSetup.cgi stack-based overflow

A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4183 — D-Link DIR-816 goahead form2WlanBasicSetup.cgi stack-based overflow

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4182 — D-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow

A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4181 — D-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow

A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
7.1 HIGH
CVE-2026-28522 — arduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of Service

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP p…

| Denial of Service
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
8.8 HIGH
CVE-2026-28519 — arduino-TuyaOpen DnsServer Heap-Based Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can se…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
7.7 HIGH
CVE-2026-28521 — arduino-TuyaOpen TuyaIoT Out-of-Bounds Memory Read Information Disclosure

arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP e…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
8.6 HIGH
CVE-2026-28520 — arduino-TuyaOpen WiFiMulti Single-Byte Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
7.2 HIGH
CVE-2016-20032 — ZKTeco ZKAccess Security System 5.3.1 Stored XSS

ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the …

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.8 MEDIUM
CVE-2016-20031 — ZKTeco ZKBioSecurity 3.0 Local Authorization Bypass via visLogin.jsp

ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers …

| Authentication
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
9.8 CRITICAL
CVE-2016-20030 — ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attac…

Remote | Authentication
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.9 MEDIUM
CVE-2016-20029 — ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipu…

| Path Traversal
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
5.3 MEDIUM
CVE-2016-20028 — ZKTeco ZKBioSecurity 3.0 Cross-Site Request Forgery Superadmin

ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Atta…

Remote | Cross-Site Request Forgery
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.1 MEDIUM
CVE-2016-20027 — ZKTeco ZKBioSecurity 3.0 Multiple Reflected XSS Vulnerabilities

ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script code by injecting malicious payloads through unsani…

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
Showing 20 of 5290 Results