Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-5018 — code-projects Simple Food Order System Parameter register-router.php sql injection

A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulat…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-5017 — code-projects Simple Food Order System Parameter all-tickets.php sql injection

A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manip…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-5016 — elecV2 elecV2P URL mock eAxios server-side request forgery

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-si…

Remote | Server-Side Request Forgery
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.3 MEDIUM
CVE-2026-5015 — elecV2 elecV2P Endpoint logs cross site scripting

A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /logs of the component Endpoint. This manipulation of the argument filename cause…

Remote | Cross-Site Scripting
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.5 MEDIUM
CVE-2026-5014 — elecV2 elecV2P Wildcard log path.join path traversal

A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log/ of the component Wildcard Handler. The manipulation results in path traversal…

Remote | Path Traversal
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.5 MEDIUM
CVE-2026-5013 — elecV2 elecV2P :key path.join path traversal

A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key. The manipulation of the argument URL leads to path traversal. The attack is p…

Remote | Path Traversal
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-5012 — elecV2 elecV2P rpc pm2run os command injection

A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing a manipulation can lead to os command injection. The attack can be executed rem…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
6.5 MEDIUM
CVE-2026-5011 — elecV2 elecV2P JSON webhook runJSFile code injection

A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the file /webhook of the component JSON Parser. Performing a manipulation of the argum…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.3 MEDIUM
CVE-2026-5007 — kazuph mcp-docs-rag add_git_repository/add_text_file index.ts cloneRepository os command …

A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file src/index.ts of the component add_git_repository/add_text_file. The manipulatio…

| Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
0.0 NA
CVE-2026-3256 — HTTP::Session versions through 0.53 for Perl defaults to using insecurely generated sessi…

HTTP::Session versions through 0.53 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash se…

| Cryptography
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
0.0 NA
CVE-2025-15604 — Amon2 versions before 6.17 for Perl use an insecure random_string implementation for secu…

Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.06 through 6.16, the random_string function will attempt to read bytes from the…

| Cryptography
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
9.0 HIGH
CVE-2026-5004 — Wavlink WL-WN579X3-C UPNP firewall.cgi sub_4019FC stack-based overflow

A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin/firewall.cgi of the component UPNP Handler. Executing a manipulation of the ar…

Remote | Memory Corruption
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.5 MEDIUM
CVE-2026-5003 — PromtEngineer localGPT Web api_server.py handle_index information disclosure

A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the function handle_index of the file rag_system/api_server.py of the component Web In…

Remote | Information Disclosure
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-5002 — PromtEngineer localGPT LLM Prompt server.py _route_using_overviews injection

A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted element is the function _route_using_overviews of the file backend/server.py of t…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-5001 — PromtEngineer localGPT server.py do_POST unrestricted upload

A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is the function do_POST of the file backend/server.py. This manipulation causes un…

Remote | Misconfiguration
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-5000 — PromtEngineer localGPT API Endpoint server.py LocalGPTHandler missing authentication

A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of the file backend/server.py of the component API Endp…

Remote | Authentication
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
6.5 MEDIUM
CVE-2026-4999 — z-9527 admin isImg Check upload.js uploadFile path traversal

A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue affects the function uploadFile of the file /server/utils/upload.js of the compon…

Remote | Path Traversal
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-4998 — Sinaptik AI PandasAI Chat Message code_executor.py CodeExecutor.execute code injection

A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the compo…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.5 MEDIUM
CVE-2026-4997 — Sinaptik AI PandasAI sql_sanitizer.py is_sql_query_safe path traversal

A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results i…

Remote | Path Traversal
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-4996 — Sinaptik AI PandasAI pandasai-lancedb Extension lancedb.py get_relevant_docs_by_id sql in…

A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_ques…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
Showing 20 of 6008 Results