Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-2174 — code-projects Contact Management System CRUD Endpoint improper authentication

A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in imprope…

contact_management_system | Remote | Authentication
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2173 — code-projects Online Examination System login.php sql injection

A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/pa…

online_examination_system | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2172 — code-projects Online Application System for Admission Login Endpoint index.php sql inject…

A vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the compone…

Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2171 — code-projects Online Student Management System Login accounts.php sql injection

A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argu…

online_student_management_system | Remote | Injection
Feb 08, 2026 Feb 23, 2026
Feb 08, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-2169 — D-Link DWR-M921 formLtefotaUpgradeFibocom command injection

A vulnerability has been found in D-Link DWR-M921 1.1.50. This impacts an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command i…

dwr-m921_firmware dwr-m921 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
8.8 HIGH
CVE-2026-2168 — D-Link DWR-M921 formLtefotaUpgradeQuectel sub_419920 command injection

A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injectio…

dwr-m921_firmware dwr-m921 | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
Showing 20 of 5066 Results