Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-5042 — Belkin F9K1122 Parameter formCrossBandSwitch stack-based overflow

A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch of the file /goform/formCrossBandSwitch of the component Parameter Handler. The…

| Memory Corruption
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
5.8 MEDIUM
CVE-2026-5041 — code-projects Chamber of Commerce Membership Management System pageMail.php fwrite comman…

A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument …

Remote | Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
4.8 MEDIUM
CVE-2026-5037 — mxml mxmlIndexNew mxml-index.c index_sort stack-based overflow

A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew. Executing a manipulation of the argument tempr c…

| Memory Corruption
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
9.0 HIGH
CVE-2026-5036 — Tenda 4G06 Endpoint DhcpListClient fromDhcpListClient stack-based overflow

A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the component Endpoint. Performing a manipulation…

Remote | Memory Corruption
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
7.5 HIGH
CVE-2026-5035 — code-projects Accounting System Parameter view_work.php sql injection

A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en…

Remote | Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
7.5 HIGH
CVE-2026-5034 — code-projects Accounting System Parameter edit_costumer.php sql injection

A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation…

Remote | Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
7.5 HIGH
CVE-2026-5033 — code-projects Accounting System Parameter view_costumer.php sql injection

A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The …

Remote | Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
5.3 MEDIUM
CVE-2026-5031 — BichitroGan ISP Billing Software Endpoint users-view resource injection

A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The manipulation of the a…

Remote | Path Traversal
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
6.5 MEDIUM
CVE-2026-5030 — Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection

A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipul…

Remote | Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
9.0 HIGH
CVE-2026-5024 — D-Link DIR-513 formSetEmail stack-based overflow

A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formSetEmail. Performing a manipulation of the argument curTime results in stack-bas…

Remote | Memory Corruption
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
5.3 MEDIUM
CVE-2026-5023 — DeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injection

A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function getCodebase/getRemoteCodebase/saveCodebase of the …

| Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
9.0 HIGH
CVE-2026-5021 — Tenda F453 httpd PPTPUserSetting fromPPTPUserSetting stack-based overflow

A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. This manipulation of the argument delno causes s…

Remote | Memory Corruption
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
6.4 MEDIUM
CVE-2026-2602 — Twentig <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'featured…

The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to insufficient input sanitization…

Remote | Cross-Site Scripting
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
6.5 MEDIUM
CVE-2026-5020 — Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection

A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The ma…

a3600r_firmware | Remote | Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
0.0 NA
CVE-2026-4851 — GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe …

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects t…

| Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
7.5 HIGH
CVE-2026-5019 — code-projects Simple Food Order System Parameter all-orders.php sql injection

A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parame…

Remote | Injection
Mar 29, 2026 Mar 29, 2026
Mar 29, 2026
Mar 29, 2026
7.5 HIGH
CVE-2026-5018 — code-projects Simple Food Order System Parameter register-router.php sql injection

A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulat…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-5017 — code-projects Simple Food Order System Parameter all-tickets.php sql injection

A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manip…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-5016 — elecV2 elecV2P URL mock eAxios server-side request forgery

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-si…

Remote | Server-Side Request Forgery
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.3 MEDIUM
CVE-2026-5015 — elecV2 elecV2P Endpoint logs cross site scripting

A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /logs of the component Endpoint. This manipulation of the argument filename cause…

Remote | Cross-Site Scripting
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
Showing 20 of 5915 Results