Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-6033 — CodeAstro Online Classroom updatedetailsfromstudent.php sql injection

A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fna…

Remote | Injection
Apr 10, 2026 Apr 29, 2026
Apr 10, 2026
Apr 29, 2026
5.3 MEDIUM
CVE-2026-6032 — code-projects Simple Laundry System checkcheckout.php cross site scripting

A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkcheckout.php. Performing a manipulation of the argument serviceId results in c…

simple_laundry_system | Remote | Cross-Site Scripting
Apr 10, 2026 Apr 29, 2026
Apr 10, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-6031 — code-projects Simple IT Discussion Forum add-category-function.php sql injection

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the file /add-category-function.php. Such manipulation of the argument Category lea…

Remote | Injection
Apr 10, 2026 Apr 29, 2026
Apr 10, 2026
Apr 29, 2026
6.0 MEDIUM
CVE-2026-5525 — Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS

A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trai…

| Memory Corruption
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.4 MEDIUM
CVE-2026-40212 — OpenStack Skyline DOM-Based Cross-Site Scripting (XSS)

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where …

Remote | Cross-Site Scripting
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-22750 — SSL bundle configuration silently bypassed in Spring Cloud Gateway

When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. …

Remote | Misconfiguration
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
Showing 20 of 5566 Results