Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.3

    HIGH
    CVE-2026-2192

    A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys.schedulereboot.start_time/sys.schedulereboot.end_time leads to stack-based ... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Memory Corruption
  • 8.3

    HIGH
    CVE-2026-2191

    A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has b... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2026-2190

    A security flaw has been discovered in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/user/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2026-2189

    A vulnerability was identified in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/report/index.php. The manipulation of the argument ay leads to sql injection. The attack can be initiated remotely. The exp... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 8.3

    HIGH
    CVE-2026-2188

    A vulnerability was determined in UTT 进取 521G 3.1.1-190816. The impacted element is the function sub_446B18 of the file /goform/formPdbUpConfig. Executing a manipulation of the argument policyNames can lead to os command injection. It is possible to launc... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 9.0

    HIGH
    CVE-2026-2187

    A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. It is possible to initiate ... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2026-2186

    A vulnerability has been found in Tenda RX3 16.03.13.11. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument list leads to stack-based buffer overflow. The attack may be performed from remote. The ... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2026-2185

    A flaw has been found in Tenda RX3 16.03.13.11. This issue affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. This manipulation of the argument devName/mac causes stack-based buffer... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2026-2184

    A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This vulnerability affects unknown code of the file /restructured/csv.php. The manipulation of the argument photo results in os ... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2026-2183

    A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestricted upload. Rem... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Misconfiguration
  • 8.3

    HIGH
    CVE-2026-2182

    A weakness has been identified in UTT 进取 521G 3.1.1-190816. Affected by this issue is the function doSystem of the file /goform/setSysAdm. Executing a manipulation of the argument passwd1 can lead to command injection. The attack may be launched remotely.... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 9.0

    HIGH
    CVE-2026-2181

    A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2026-2180

    A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation of the argument ssid_5g leads to stack-based buffer overflow. The attack can be launched remotely. The ex... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Memory Corruption
  • 5.8

    MEDIUM
    CVE-2026-2179

    A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2026-2178

    A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the argument args resul... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2026-2177

    A vulnerability has been found in SourceCodester Prison Management System 1.0. The impacted element is an unknown function of the component Login. The manipulation leads to session fixiation. It is possible to initiate the attack remotely. The exploit has... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Authentication
  • 6.5

    MEDIUM
    CVE-2026-2176

    A security vulnerability has been detected in code-projects Contact Management System 1.0. This issue affects some unknown processing of the file index.py. Such manipulation of the argument selecteditem[0] leads to sql injection. The attack can be execute... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 8.3

    HIGH
    CVE-2026-2175

    A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manipulation of the argument upnp_enable causes os command injection. Remote exploitation of the attack is poss... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2026-2174

    A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely.... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Authentication
  • 7.5

    HIGH
    CVE-2026-2173

    A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiat... Read more

    Affected Products :
    • Published: Feb. 08, 2026
    • Modified: Feb. 08, 2026
    • Vuln Type: Injection
Showing 20 of 4495 Results