Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-6038 — code-projects Vehicle Showroom Management System RegisterCustomerFunction.php sql injecti…

A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argum…

Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-6037 — code-projects Vehicle Showroom Management System AddVehicleFunction.php sql injection

A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument BR…

Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-6036 — code-projects Vehicle Showroom Management System VehicleDetailsFunction.php sql injection

A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of the ar…

Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.3 MEDIUM
CVE-2026-33457 — Potential livestatus injection in prediction graph page

Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name paramet…

checkmk | Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.1 MEDIUM
CVE-2026-33456 — Potential livestatus injection in notification test

Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via…

checkmk | Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.3 MEDIUM
CVE-2026-33455 — Livestatus injection in monitoring quicksearch

Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in se…

checkmk | Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.3 MEDIUM
CVE-2026-6035 — code-projects Vehicle Showroom Management System ServiceAndSalesReport.php cross site scr…

A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unknown function of the file /BranchManagement/ServiceAndSalesReport.php. The manipu…

Remote | Cross-Site Scripting
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.3 MEDIUM
CVE-2026-6034 — code-projects Vehicle Showroom Management System ProfitAndLossReport.php cross site scrip…

A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /BranchManagement/ProfitAndLossReport.php. Executing a manipulation of the a…

Remote | Cross-Site Scripting
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
6.5 MEDIUM
CVE-2026-6033 — CodeAstro Online Classroom updatedetailsfromstudent.php sql injection

A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fna…

Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.3 MEDIUM
CVE-2026-6032 — code-projects Simple Laundry System checkcheckout.php cross site scripting

A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkcheckout.php. Performing a manipulation of the argument serviceId results in c…

simple_laundry_system | Remote | Cross-Site Scripting
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-6031 — code-projects Simple IT Discussion Forum add-category-function.php sql injection

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the file /add-category-function.php. Such manipulation of the argument Category lea…

Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
6.0 MEDIUM
CVE-2026-5525 — Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS

A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trai…

| Memory Corruption
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
5.4 MEDIUM
CVE-2026-40212 — OpenStack Skyline DOM-Based Cross-Site Scripting (XSS)

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where …

Remote | Cross-Site Scripting
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-22750 — SSL bundle configuration silently bypassed in Spring Cloud Gateway

When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. …

Remote | Misconfiguration
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
6.5 MEDIUM
CVE-2026-6030 — itsourcecode Construction Management System del1.php sql injection

A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /del1.php. This manipulation of the argument toolname causes sql inje…

Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
10.0 HIGH
CVE-2026-6029 — Totolink A7100RU CGI cstecgi.cgi setVpnAccountCfg os command injection

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipul…

a7100ru_firmware | Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
10.0 HIGH
CVE-2026-6028 — Totolink A7100RU CGI cstecgi.cgi setPptpServerCfg os command injection

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manip…

a7100ru_firmware | Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
10.0 HIGH
CVE-2026-6027 — Totolink A7100RU CGI cstecgi.cgi setUrlFilterRules os command injection

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a m…

a7100ru_firmware | Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
10.0 HIGH
CVE-2026-6026 — Totolink A7100RU CGI cstecgi.cgi setPortalConfWeChat os command injection

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler…

a7100ru_firmware | Remote | Injection
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
6.5 MEDIUM
CVE-2026-4432 — YITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOR

The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function …

Remote | Authorization
Apr 10, 2026 Apr 15, 2026
Apr 10, 2026
Apr 15, 2026
Showing 20 of 6472 Results