Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-5543 — PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php s…

A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected element is an unknown function of the file /admin/yesterday-reg-users.php. The mani…

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.3 MEDIUM
CVE-2026-5542 — code-projects Simple Laundry System Parameter modstaffinfo.php cross site scripting

A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation o…

Remote | Cross-Site Scripting
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.3 MEDIUM
CVE-2026-5541 — code-projects Simple Laundry System Parameter modmemberinfo.php cross site scripting

A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /modmemberinfo.php of the component Parameter Handler. Performing a manipu…

Remote | Cross-Site Scripting
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
7.5 HIGH
CVE-2026-5540 — code-projects Simple Laundry System Parameter modifymember.php sql injection

A vulnerability has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modifymember.php of the component Parameter Handler. Such manipulation …

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
6.4 MEDIUM
CVE-2026-5590 — net: ip/tcp: Null pointer dereference can be triggered by a race condition

A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL…

Remote | Race Condition
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.3 MEDIUM
CVE-2026-5539 — code-projects Simple Laundry System Parameter modifymember.php cross site scripting

A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember.php of the component Parameter Handler. This manipulation of the argument firs…

Remote | Cross-Site Scripting
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
6.5 MEDIUM
CVE-2026-5538 — QingdaoU OnlineJudge judge_server_heartbeat Endpoint JudgeServer.service_url server-side …

A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_url of the component judge_server_heartbeat Endpoi…

Remote | Server-Side Request Forgery
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
6.5 MEDIUM
CVE-2026-5537 — halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection

A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the …

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
7.5 HIGH
CVE-2026-5536 — FedML-AI FedML gRPC server grpc_server.py sendMessage deserialization

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deseri…

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.3 MEDIUM
CVE-2026-5535 — FedML-AI FedML MQTT Message FileUtils.java path traversal

A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the …

Remote | Path Traversal
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
7.5 HIGH
CVE-2026-5534 — itsourcecode Online Enrollment System Parameter index.php sql injection

A vulnerability was identified in itsourcecode Online Enrollment System 1.0. This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the component Parameter Handler. Such …

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.3 MEDIUM
CVE-2026-5533 — badlogic pi-mono SVG Artifact SvgArtifact.ts cross site scripting

A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Han…

Remote | Cross-Site Scripting
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
7.5 HIGH
CVE-2026-5532 — ScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_ex…

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the co…

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.5 MEDIUM
CVE-2026-5531 — SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cl…

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. Th…

Remote | Information Disclosure
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
6.5 MEDIUM
CVE-2026-5530 — Ollama Model Pull API download.go server-side request forgery

A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side…

ollama | Remote | Server-Side Request Forgery
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.3 MEDIUM
CVE-2026-5529 — Dromara lamp-cloud DefUserController pageUser improper authorization

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipul…

Remote | Authorization
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
6.5 MEDIUM
CVE-2026-5528 — MoussaabBadla code-screenshot-mcp HTTP os command injection

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command inject…

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.5 MEDIUM
CVE-2026-5527 — Tenda 4G03 Pro ECDSA P-256 Private Key server.key hard-coded key

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Pr…

Remote | Cryptography
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
7.5 HIGH
CVE-2026-5526 — Tenda 4G03 Pro httpd access control

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation result…

Remote | Authorization
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.7 HIGH
CVE-2018-25246 — Wikipedia 12.0 Denial of Service via Search

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can …

Remote | Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
Showing 20 of 5875 Results