Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-4572 — SourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection

A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /view_product.php of the component HTTP POST Request …

sales_and_inventory_system | Remote | Injection
Mar 23, 2026 Apr 10, 2026
Mar 23, 2026
Apr 10, 2026
6.5 MEDIUM
CVE-2026-4571 — SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injecti…

A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_payments.php of the component HTTP P…

sales_and_inventory_system | Remote | Injection
Mar 23, 2026 Apr 10, 2026
Mar 23, 2026
Apr 10, 2026
8.8 HIGH
CVE-2026-4570 — SourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql inject…

A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manip…

sales_and_inventory_system | Remote | Injection
Mar 23, 2026 Apr 07, 2026
Mar 23, 2026
Apr 07, 2026
6.5 MEDIUM
CVE-2025-10736 — ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Review…

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authori…

reviewx | Remote | Authorization
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2026-4569 — SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injecti…

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of the component HTTP POST Request Handler. This manip…

sales_and_inventory_system | Remote | Injection
Mar 23, 2026 Apr 10, 2026
Mar 23, 2026
Apr 10, 2026
6.5 MEDIUM
CVE-2026-4568 — SourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql inject…

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /update_supplier.php of the component HTTP GET Request Handler. The manipulati…

sales_and_inventory_system | Remote | Injection
Mar 23, 2026 Apr 18, 2026
Mar 23, 2026
Apr 18, 2026
10.0 HIGH
CVE-2026-4567 — Tenda A15 UploadCfg stack-based overflow

A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buff…

a15_firmware a15 | Remote | Memory Corruption
Mar 23, 2026 Apr 02, 2026
Mar 23, 2026
Apr 02, 2026
9.0 HIGH
CVE-2026-4566 — Belkin F9K1122 formWISP5G stack-based overflow

A flaw has been found in Belkin F9K1122 1.00.33. The affected element is the function formWISP5G of the file /goform/formWISP5G. Executing a manipulation of the argument webpage can lead to stack-bas…

f9k1122_firmware | Remote | Memory Corruption
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
10.0 CRITICAL
CVE-2026-4606 — GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege

GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system.  During installation…

Remote | Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
Showing 20 of 6309 Results