Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-3806 — SourceCodester/janobe Resort Reservation System room_rates.php sql injection

A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown processing of the file /room_rates.php. This manipulation of the argument q caus…

resort_reservation_system | Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3804 — Tenda i3 WifiMacFilterSet formWifiMacFilterSet stack-based overflow

A security flaw has been discovered in Tenda i3 1.0.0.6(2204). This vulnerability affects the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet. The manipulation of the argument inde…

Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3803 — Tenda i3 WifiMacFilterGet formWifiMacFilterGet stack-based overflow

A vulnerability was identified in Tenda i3 1.0.0.6(2204). This affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. The manipulation of the argument index leads to stack-ba…

Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.8 HIGH
CVE-2026-30896 — Qsee Client DLL Loading Privilege Escalation Vulnerability

The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some malicious DLL to the same directory and execute the affecte…

| Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3802 — Tenda i3 exeCommand formexeCommand stack-based overflow

A vulnerability was determined in Tenda i3 1.0.0.6(2204). Affected by this issue is the function formexeCommand of the file /goform/exeCommand. Executing a manipulation of the argument cmdinput can l…

Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.3 HIGH
CVE-2026-3822 — Taipower|Taipower APP - Improper Certificate Validation

Taipower APP developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL…

taipower_app | Remote | Cryptography
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3801 — Tenda i3 setAutoPing formSetAutoPing stack-based overflow

A vulnerability was found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formSetAutoPing of the file /goform/setAutoPing. Performing a manipulation of the argument ping1/pi…

Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3800 — SourceCodester/janobe Resort Reservation System controller.php doInsert unrestricted uplo…

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument imag…

resort_reservation_system | Remote | Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3799 — Tenda i3 setcfm formSetCfm stack-based overflow

A flaw has been found in Tenda i3 1.0.0.6(2204). This impacts the function formSetCfm of the file /goform/setcfm. This manipulation of the argument funcpara1 causes stack-based buffer overflow. Remot…

Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
5.8 MEDIUM
CVE-2026-3798 — Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injection

A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component Request Path Handler. T…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3797 — Tiandy Video Surveillance System 视频监控平台 CLS_REST_File.java uploadFile unrestricted upload

A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile of the file /src/com/tiandy/easy7/core/rest/CLS_REST_File…

Remote | Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
5.3 MEDIUM
CVE-2026-3796 — Qi-ANXIN QAX Virus Removal Mini Filter Driver QKSecureIO_Imp.sys ZwTerminateProcess acces…

A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter D…

| Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3631 — Buffer Over-read DoS Vulnerability in COMMGR2

Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.

commgr2 | Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3630 — Stack-based Buffer Overflow Vulnerability in COMMGR2

Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.

commgr2 | Remote | Memory Corruption
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3795 — doramart DoraCMS v1.js createFileBypath path traversal

A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a manipulation results in path tr…

Remote | Path Traversal
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3794 — doramart DoraCMS Email API send improper authentication

A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper auth…

Remote | Authentication
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3793 — SourceCodester Sales and Inventory System GET Parameter sales_invoice1.php sql injection

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file sales_invoice1.php of the component GET Parameter Handler. This ma…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3792 — SourceCodester Sales and Inventory System GET Parameter purchase_invoice.php sql injection

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchase_invoice.php of the component GET Parameter Handler. The manipulation of t…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3791 — SourceCodester Sales and Inventory System Search dashboard.php sql injection

A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file dashboard.php of the component Search. The manipulati…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3790 — SourceCodester Sales and Inventory System POST Parameter check_supplier_details.php sql i…

A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file check_supplier_details.php of the component POST Paramet…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
Showing 20 of 5004 Results