CVE-2026-35436
Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate pri
11:18 KSA
HIGH
CVSS 8.8
CWE-1220
Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
CVE-2026-35439
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
11:18 KSA
HIGH
CVSS 8.8
CWE-502
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-40357
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
14:42 KSA
HIGH
CVSS 8.8
CWE-502
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-40365
Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code
23:32 KSA
HIGH
CVSS 8.8
CWE-1220
Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-40370
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
23:32 KSA
HIGH
CVSS 8.8
CWE-73
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-7498
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio
09:48 KSA
HIGH
CVSS 8.8
CWE-79
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS.
This issue affects DernekWeb: through 30122025.
CVE-2026-8775
Edimax BR-6428NS Buffer Overflow in L2TP Configuration Handler
01:34 KSA
HIGH
CVSS 8.8
CWE-119
A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TPUserName causes buffer overflow. It is possible to initiate the attack remotely. …
CVE-2026-8776
Edimax BR-6428NS Buffer Overflow in PPTP Setup Function (CVE-2026-8776)
01:34 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulation of the argument pptpUserName leads to buffer overflow. It is possible to launc…
CVE-2026-40358
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
14:42 KSA
HIGH
CVSS 8.4
CWE-416
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40361
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
20:44 KSA
HIGH
CVSS 8.4
CWE-416
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40363
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
20:44 KSA
HIGH
CVSS 8.4
CWE-122
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40364
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t
20:44 KSA
HIGH
CVSS 8.4
CWE-122
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40366
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
23:32 KSA
HIGH
CVSS 8.4
CWE-416
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40367
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
23:32 KSA
HIGH
CVSS 8.4
CWE-822
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-35438
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
11:18 KSA
HIGH
CVSS 8.3
CWE-862
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-40368
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
23:32 KSA
HIGH
CVSS 8.0
CWE-502
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-35417
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to
08:00 KSA
HIGH
CVSS 7.8
CWE-843
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2026-35418
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
08:00 KSA
HIGH
CVSS 7.8
CWE-367
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-35420
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
08:00 KSA
HIGH
CVSS 7.8
CWE-122
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-35421
Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
08:00 KSA
HIGH
CVSS 7.8
CWE-122
Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
CVE-2026-40359
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
17:30 KSA
HIGH
CVSS 7.8
CWE-416
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40360
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
20:44 KSA
HIGH
CVSS 7.8
CWE-125
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-40362
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
20:44 KSA
HIGH
CVSS 7.8
CWE-122
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40369
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
23:32 KSA
HIGH
CVSS 7.8
CWE-822
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-40377
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally
23:32 KSA
HIGH
CVSS 7.8
CWE-122
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
CVE-2026-40381
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
23:32 KSA
HIGH
CVSS 7.8
CWE-284
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-47092
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attac
13:16 KSA
HIGH
CVSS 7.8
CWE-427
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud per…
CVE-2026-35424
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorize
11:18 KSA
HIGH
CVSS 7.5
CWE-401
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
CVE-2026-42009
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) pac
09:48 KSA
HIGH
CVSS 7.5
CWE-475
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequen…
CVE-2026-8771
A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litem
01:34 KSA
HIGH
CVSS 7.3
CWE-74
A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql i…
CVE-2026-8785
A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the func
09:48 KSA
HIGH
CVSS 7.3
CWE-74
A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to…
CVE-2026-4999
A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue af
02:36 KSA
MEDIUM
CVSS 6.3
CWE-22
A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue affects the function uploadFile of the file /server/utils/upload.js of the component isImg Check. The manipulation of the argument fileType leads to path traversa…
CVE-2026-5011
A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the fil
02:36 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the file /webhook of the component JSON Parser. Performing a manipulation of the argument rawcode results in code injection. Remote exploitation of the attack is possi…
CVE-2026-5020
A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNotice
12:52 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may…
CVE-2026-5030
A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHos
12:52 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be ini…
CVE-2026-5126
A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. T
09:57 KSA
MEDIUM
CVSS 6.3
CWE-918
A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.
CVE-2026-5153
A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/Wr
09:57 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. Executing a manipulation of the argument mac can lead to command injection. The attack may be launched remotely. The exploit has been published and m…
CVE-2026-5177
A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function
09:57 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched rem…
CVE-2026-5178
A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the func
09:57 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument vlanPriLan3 leads to command injection. Remote exploitation of the attack is …
CVE-2026-5181
A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some un
09:57 KSA
MEDIUM
CVSS 6.3
CWE-284
A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_category. Such manipulation of the argument img leads to unrestricted upload. The a…
CVE-2026-5183
A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the
09:57 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the file /goform/addRouting. Executing a manipulation of the argument dest can lead to command injection. It is possible to launch the attack remotely. The exploit …
CVE-2026-5184
A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file
09:57 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file /goform/setSysAdm. The manipulation of the argument admuser leads to command injection. The attack can be initiated remotely. The exploit is publicly available…
CVE-2026-5196
A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the fi
09:57 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the p…
CVE-2026-5197
A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of
09:57 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public …
CVE-2026-5205
A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigge
09:57 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to server-side request forgery. The attack ca…
CVE-2026-5206
A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects
09:57 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argument Payment_id/Amount/customer_id/payment_type/customer_name leads to sql injection…
CVE-2026-5248
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app
09:57 KSA
MEDIUM
CVSS 6.3
CWE-913
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object attributes…
CVE-2026-5251
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user
09:57 KSA
MEDIUM
CVSS 6.3
CWE-913
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamically-determined object attributes. It is p…
CVE-2026-5259
A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the
09:57 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/controller/AlarmController.java of the component Alarm Preview. Executing a manipulatio…
CVE-2026-5317
A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_
09:59 KSA
MEDIUM
CVSS 6.3
CWE-119
A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be performed from remote. The exploit has been released to the public and may be used …
CVE-2026-5327
A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function h
21:30 KSA
MEDIUM
CVSS 6.3
CWE-74
A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function handleGetDiskUsage of the file src/index.ts. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The explo…
CVE-2026-5328
A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted e
21:30 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listItem of the file src/main/java/com/suisung/shopsuite/pt/service/impl/ProductIndexServiceImpl.java of the component ProductItemDao Int…
CVE-2026-5344
A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt
21:30 KSA
MEDIUM
CVSS 6.3
CWE-22
A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt_uploadImage of the file rpc/TXP_RPCServer.php of the component XML-RPC Handler. The manipulation of the argument file.name leads to path traversal. Remote expl…
CVE-2026-5351
A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setu
23:32 KSA
MEDIUM
CVSS 6.3
CWE-77
A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setup.cgi. This manipulation of the argument wl_enrolee_pin causes os command injection. The attack may be initiated remotely. The exploit has been made available t…
CVE-2026-5352
A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /se
01:52 KSA
MEDIUM
CVSS 6.3
CWE-77
A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /setup.cgi. Such manipulation of the argument pcdb_list leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly…
CVE-2026-5353
A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. P
01:52 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. Performing a manipulation of the argument c4_IPAddr results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and…
CVE-2026-5354
A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the f
01:52 KSA
MEDIUM
CVSS 6.3
CWE-77
A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the file /setup.cgi. Executing a manipulation of the argument policy_name can lead to os command injection. The attack can be executed remotely. The exploit has been…
CVE-2026-5355
A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the fil
01:52 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the file /setup.cgi. The manipulation of the argument policy_name leads to os command injection. The attack is possible to be carried out remotely. The exploit has bee…
CVE-2026-5470
A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca6
19:04 KSA
MEDIUM
CVSS 6.3
CWE-918
A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractContent of the file src/services/content-extractor.service.ts of the component Mod…
CVE-2026-5472
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Th
19:04 KSA
MEDIUM
CVSS 6.3
CWE-284
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php of the component Profile Picture Handler. This manipulation of the argument File…
CVE-2026-5474
A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw
19:04 KSA
MEDIUM
CVSS 6.3
CWE-119
A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must h…
CVE-2026-5528
A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown par
09:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed…
CVE-2026-5530
A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of
09:16 KSA
MEDIUM
CVSS 6.3
CWE-918
A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted e…
CVE-2026-5532
A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sand
09:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the component GenerateCodeNode Component. The manipulation results in os command inject…
CVE-2026-5537
A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the functio
11:32 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the component HTTP GET Parameter Handler. The manipulation of the argument seid leads…
CVE-2026-5538
A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of
13:48 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_url of the component judge_server_heartbeat Endpoint. The manipulation results in server-side request forgery. It is possible to la…
CVE-2026-6191
SQL Injection in itsourcecode Construction Management System 1.0 /equipments.php
00:32 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publ…
CVE-2026-6571
KodExplorer Authorization Bypass via roleGroupAction Parameter Manipulation
19:16 KSA
MEDIUM
CVSS 6.3
CWE-285
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may…
CVE-2026-6573
PHPEMS 11.0 Server-Side Request Forgery in Exam Creation Handler
19:17 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attack can be …
CVE-2026-6576
DjangoBlog Command Injection in WeChat Bot Interface (CVE-2026-6576)
01:53 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat Bot Interface. Executing a manipulation of the argument Source can lead to command injec…
CVE-2026-6586
Authorization Bypass in TransformerOptimus SuperAGI Budget Endpoint
06:54 KSA
MEDIUM
CVSS 6.3
CWE-285
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the…
CVE-2026-6609
DjangoBlog OAuth Authorization Bypass via oauthid Parameter Manipulation
14:00 KSA
MEDIUM
CVSS 6.3
CWE-266
A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This manipulation of the argument oauthid causes improper authorization. The attack may be initiated remotely. The exploit has been publishe…
CVE-2026-6626
Cockpit-HQ Cockpit Input Validation Vulnerability in Asset/Aggregate Handler
20:32 KSA
MEDIUM
CVSS 6.3
CWE-20
A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler. The manipulation results in improper neutralization of special elements in data query logic. It is possible to l…
CVE-2026-6628
SQL Injection in Ecclesia CRM Query Viewer Component ValidateInput Function
20:32 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query Viewer Component. This manipulation of the argument custom causes sql injection. The attack can be initiated remotely. The exploit…
CVE-2026-6634
usememos Authorization Bypass via additionalStyle/additionalScript Manipulation
20:32 KSA
MEDIUM
CVSS 6.3
CWE-266
A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting. This manipulation of the argument additionalStyle/additionalScript causes improper authorization. The attack…
CVE-2026-6649
Qibo CMS 1.0 Server-Side Request Forgery in Image Headers
20:32 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a manipulation of the argument starts can lead to server-side request forgery. The attack can be launched remotely. The exploit has bee…
CVE-2026-6729
HKUDS OpenHarness Session Key Derivation Vulnerability
05:48 KSA
MEDIUM
CVSS 6.3
CWE-287
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attack…
CVE-2026-6744
Bagisto SSRF Vulnerability in Downloadable Link Handler (CVE-2026-6744)
02:50 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendo…
CVE-2026-6799
Comfast CF-N1-S Command Injection via Ping Configuration Endpoint
21:40 KSA
MEDIUM
CVSS 6.3
CWE-74
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config?method=SET§ion=ping_config of the component Endpoint. Performing a manipulation of the argument destination results in command…
CVE-2026-6982
ShowDoc SQL Injection in API Page Sort Endpoint (CVE-2026-6982)
23:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Controller/PageController.class.PHP of the component API Page Sort Endpoint. Executing a manipulation of the …
CVE-2026-7196
SQL Injection in CodeAstro Online Classroom 1.0 /guestdetails deleteid Parameter
06:18 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publ…
CVE-2026-7229
SQL Injection in Coaching Management System 1.0 POST Handler
15:00 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manipulation of the argument complaintreply results in sql injection. It is possible t…
CVE-2026-7264
SQL Injection in SourceCodester Pizzafy Ecommerce System 1.0 Cart Function
20:07 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?action=get_cart_items. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. Th…
CVE-2026-7265
SQL Injection in SourceCodester Pizzafy Ecommerce Category Function
22:54 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file pizza/index.php?page=category. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is pos…
CVE-2026-7266
SQL Injection in SourceCodester Pizzafy Ecommerce System 1.0 save_order Function
22:54 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.php?action=save_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The explo…
CVE-2026-7267
SQL Injection in SourceCodester Pizzafy Ecommerce System 1.0 /view_prod.php
22:54 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view_prod.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may …
CVE-2026-7268
SQL Injection in SourceCodester Pizzafy Ecommerce System 1.0
22:54 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category of the file /admin/ajax.php?action=save_category. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote. The exp…
CVE-2026-7290
JeecgBoot SQL Injection in loadDict Endpoint (CVE-2026-7290)
01:48 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boot/jeecg-boot-base-core/src/main/java/org/jeecg/common/util/SqlInjectionUtil.java of the component loadDict Endpoint. This manipulation of the argument keyword c…
CVE-2026-7291
o2oa FileAction SSRF Vulnerability via fileUrl Parameter Manipulation
04:18 KSA
MEDIUM
CVSS 6.3
CWE-918
A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of the component URL Fetching. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. It is possible to launch the attack remotel…
CVE-2026-7305
xxl-job Server-Side Request Forgery in triggerJob Function
09:00 KSA
MEDIUM
CVSS 6.3
CWE-918
A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addres…
CVE-2026-7391
SQL Injection in SourceCodester Pharmacy System 1.0 save_supplier Function
13:36 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action=save_supplier. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The explo…
CVE-2026-7447
SQL Injection in SourceCodester Pet Grooming Management Software 1.0
20:09 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the argument type/length/business parameter validity causes sql injection. The attack is possible to …
CVE-2026-7469
Tenda 4G300 Remote Command Injection via DelFil Parameter
22:36 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and…
CVE-2026-7602
JeecgBoot FillRuleUtil Improper Authorization via ruleClass Parameter
11:32 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the component FillRuleUtil Component. The manipulation of the argument ruleClass results in improper authorization. The attack may be p…
CVE-2026-7603
JeecgBoot FileDownloadUtils SSRF Vulnerability (CVE-2026-7603)
11:32 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch of the file FileDownloadUtils.jav of the component LoadFile Endpoint. This manipulation of the argument files causes server-side request forgery. It is possible…
CVE-2026-7604
JeecgBoot OpenApi Service SSRF Vulnerability via originUrl Parameter
11:32 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiController.call of the file OpenApiController.java of the component OpenApi Service. Such manipulation of the argument originUrl database leads to server-side request f…
CVE-2026-7605
JeecgBoot SSRF in Image Upload Functionality (CVE-2026-7605)
14:00 KSA
MEDIUM
CVSS 6.3
CWE-918
A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file CommonController.java of the compon…
CVE-2026-7609
TRENDnet TEW-821DAP OS Command Injection in Diagnostic Tool
18:48 KSA
MEDIUM
CVSS 6.3
CWE-77
A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploi…
CVE-2026-7627
Path Traversal in 8nite MetaTrader-4-MCP 1.0.0 ea_name Parameter
18:48 KSA
MEDIUM
CVSS 6.3
CWE-22
A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file src/index.ts of the component sync_ea_from_file. Such manipulation of the argument ea_name leads to path traversal. The attack can…
CVE-2026-7628
Command Injection in crazyrabbitLTC mcp-code-review-server RepoMix Handler
18:48 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be initiat…
CVE-2026-7629
Command Injection in kleneway awesome-cursor-mpc-server Code-Review Tool
21:36 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a manipulation can lead to command injection. The attack may be launched remotely.…
CVE-2026-7642
OS Command Injection in pskill9 website-downloader outputPath Parameter
21:36 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument outputPath results in os command injection. The attack may be init…
CVE-2026-7653
Command Injection in mcp-server-rijksmuseum open_image_in_browser Function
00:00 KSA
MEDIUM
CVSS 6.3
CWE-77
A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument imageUrl results in os command injection. The atta…
CVE-2026-7672
SQL Injection in youlai-boot getUserList Endpoint via Argument Order Manipulation
08:00 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.java of the component Users Endpoint. Such manipulation of the argument order leads …
CVE-2026-7678
SQL Injection in YunaiV yudao-cloud GoViewDataServiceImpl getDataBySQL
13:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file yudao-module-report-biz/src/main/java/io/github/ruoyi/report/service/impl/GoViewDataServiceImpl.java. Such manipulation leads to sql injection. It is possible to…
CVE-2026-7682
Edimax BR-6208AC L2TP Command Injection Vulnerability (CVE-2026-7682)
13:18 KSA
MEDIUM
CVSS 6.3
CWE-74
A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPUserName results in command injection. It is possible to launch the attack remotel…
CVE-2026-7683
Edimax BR-6428nC Command Injection in Web Interface /goform/setWAN
13:18 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the argument pppUserName/pptpUserName causes command injection. The attack can be initiated remotely. Th…
CVE-2026-7687
Command Injection in langflow-ai CodeParser Module Handler
15:20 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was determined in langflow-ai langflow up to 1.8.4. Affected by this issue is the function CodeParser.parse_callable_details of the file src/lfx/src/lfx/custom/code_parser/code_parser.py of the component Full Builtins Module Handler. Executing a manipulation can l…
CVE-2026-7690
Wavlink WL-WN570HA1 Command Injection via Username Parameter
17:36 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit ha…
CVE-2026-7691
Wavlink WL-WN570HA1 Command Injection in adm.cgi set_sys_cmd Function
17:36 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. Impacted is the function set_sys_cmd of the file /cgi-bin/adm.cgi. Such manipulation of the argument command leads to command injection. It is possible to launch the attack remotely. The exploi…
CVE-2026-7692
Wavlink WL-WN570HA1 Command Injection via DDNS Parameter
17:36 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS results in command injection. The attack can be initiated remotely. The exploit is …
CVE-2026-7696
Acrel EEMS 1.3.0 Unrestricted File Upload Vulnerability
20:07 KSA
MEDIUM
CVSS 6.3
CWE-284
A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack m…
CVE-2026-7699
SQL Injection in Dromara MaxKey StrUtils.checkSqlInjection Function
22:26 KSA
MEDIUM
CVSS 6.3
CWE-74
A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file StrUtils.java. Performing a manipulation of the argument filtersfields results in sql injection. The attack is possible to be carried …
CVE-2026-7700
Code Injection in langflow-ai LambdaFilterComponent eval Function
22:26 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p of the component LambdaFilterComponent. Executing a manipulation can lead to code injection. The attack may be …
CVE-2026-7705
JD Cloud JDCOS Command Injection via set_iptv_info vid Parameter
06:48 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in JD Cloud JDCOS 4.5.1.r4518. This vulnerability affects the function set_iptv_info of the file /jdcap of the component Service Interface. Executing a manipulation of the argument vid can lead to command injection. It is possible to launch the attack remote…
CVE-2026-7709
Calibre-Web Improper Authorization in generate_auth_token Function
06:48 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token of the file cps/kobo_auth.py of the component Endpoint. Such manipulation of the argument user_id leads to improper authorization. The attack may be launc…
CVE-2026-7712
MindsDB Pickle Deserialization Remote Code Execution (CVE-2026-7712)
06:48 KSA
MEDIUM
CVSS 6.3
CWE-20
A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may …
CVE-2026-7713
Improper Authorization in Calibre-Web-Automated Kobo Auth-Token Route
06:48 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack…
CVE-2026-7716
SQL Injection in Gym Management System PHP /index.php day Parameter
09:18 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /index.php. Performing a manipulation of the argument day results in sql injection. The attack can be initiated remotely. The exploit ha…
CVE-2026-7718
Totolink WA300 Command Injection via setWebWlanIdx Parameter
09:18 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was identified in Totolink WA300 5.2cu.7112_B20190227. Impacted is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument webWlanIdx leads to command injection. The attack may be initiate…
CVE-2026-7720
Totolik WA300 Command Injection in setLanguageCfg Function
09:18 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument langType causes command injection. Remote exploitat…
CVE-2026-7721
Totolink WA300 Remote Command Injection via NTP hostTime Parameter
09:18 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in Totolink WA300 5.2cu.7112_B20190227. This affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument hostTime leads to command injection. The attack can be executed remotely. The exploit h…
CVE-2026-7725
PrefectHQ Prefect GitRepository Argument Injection Vulnerability
11:54 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in PrefectHQ prefect up to 3.6.25.dev6. Affected by this issue is some unknown functionality of the file src/prefect/runner/storage.py of the component GitRepository Pull Handler. The manipulation of the argument commit_sha/directories results in argumen…
CVE-2026-7728
Path Traversal in mcp-rtfm 0.1.0 MCP Interface Document Functions
11:54 KSA
MEDIUM
CVSS 6.3
CWE-22
A vulnerability was identified in ryanjoachim mcp-rtfm 0.1.0. This vulnerability affects the function get_doc_content/read_doc/update_doc of the component MCP Interface. Such manipulation of the argument docFile leads to path traversal. The attack can be launched remotely. The ex…
CVE-2026-7729
Server-Side Request Forgery in pixelsock directus-mcp 1.0.0 validateUrl
11:54 KSA
MEDIUM
CVSS 6.3
CWE-918
A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Performing a manipulation of the argument fileUrl results in server-side request forgery. The attack may be initia…
CVE-2026-7730
OS Command Injection in privsim mcp-test-runner 0.2.0 MCP Interface
11:54 KSA
MEDIUM
CVSS 6.3
CWE-77
A weakness has been identified in privsim mcp-test-runner 0.2.0. Impacted is the function child_process.spawn of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument command can lead to os command injection. The attack may be launched rem…
CVE-2026-7731
SQL Injection in BloodBank Managing System 1.0 get_state.php
14:48 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file get_state.php. The manipulation of the argument G_STATE_ID leads to sql injection. Remote exploitation of the attack is possible. The…
CVE-2026-7732
BloodBank Managing System 1.0 Unrestricted File Upload Vulnerability
14:48 KSA
MEDIUM
CVSS 6.3
CWE-284
A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.
CVE-2026-7738
Path Traversal in puchunjie doc-tools-mcp 1.0.18 MCP Interface
14:48 KSA
MEDIUM
CVSS 6.3
CWE-22
A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-server.ts of the component MCP Interface. The manipulation of the argument filePath results in path traversal. The attack can be laun…
CVE-2026-7741
SQL Injection in CodeAstro Online Classroom 1.0 Student Login
14:48 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/studentlogin. Performing a manipulation of the argument sid results in sql injection. Remote exploitation of the attack is possible. The exploit is now pub…
CVE-2026-7742
SQL Injection in CodeAstro Online Classroom Faculty Login Module
14:48 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /OnlineClassroom/facultylogin. Executing a manipulation of the argument fid can lead to sql injection. The attack can be executed remotely. The exploit has been publis…
CVE-2026-7743
CodeAstro Online Classroom 1.0 SQL Injection in studentdetails deleteid Parameter
14:48 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdetails. The manipulation of the argument deleteid leads to sql injection. The attack is possible to be carried out remotely. The expl…
CVE-2026-7744
SQL Injection in CodeAstro Online Classroom 1.0 fname Parameter
17:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipulation of the argument fname results in sql injection. The attack may be performed from remote. The exploit has been made public and…
CVE-2026-7745
SQL Injection in CodeAstro Online Classroom facultydetails Parameter
17:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineClassroom/facultydetails. This manipulation of the argument deleteid causes sql injection. It is possible to initiate the attack remotely. The exploit has been pu…
CVE-2026-7746
SQL Injection in SourceCodester Pharmacy Management System 1.0
17:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /product_expiry/edit-admin.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely…
CVE-2026-7782
Perfex CRM Authorization Bypass in Clients Project Handler
08:16 KSA
MEDIUM
CVSS 6.3
CWE-285
A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Clients.php of the component Tenant Handler. The manipulation of the argument ID results in authorization bypass. The attack may be pe…
CVE-2026-8185
UGREEN CM933 Administrative Interface Missing Authentication Vulnerability
17:26 KSA
MEDIUM
CVSS 6.3
CWE-287
A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative Interface. Such manipulation leads to missing authentication. The attack requires being on the local network. You should upgrade the…
CVE-2026-8190
Wavlink NU516U1 OS Command Injection in WAN Configuration
02:37 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway is directly passed by the attacker/so we can control …
CVE-2026-8191
Wavlink NU516U1 Remote OS Command Injection via wifi_region Function
02:37 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os command injection. The attack can be launched remotely. The exploit is publicly a…
CVE-2026-8192
Wavlink NU516U1 OS Command Injection via wzdap Function
02:37 KSA
MEDIUM
CVSS 6.3
CWE-77
A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/wl_Pass is directly passed by the attacker/so we can control the EncrypType/wl_Pa…
CVE-2026-8193
Akaunting 3.1.21 Invoice PDF SSRF Vulnerability in dompdf Configuration
02:37 KSA
MEDIUM
CVSS 6.3
CWE-918
A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php of the component Invoice PDF Rendering. Executing a manipulation can lead to server-side request forgery. The attack may be launched remotely. The exploit …
CVE-2026-8217
OS Command Injection in IAS Canias ERP 8.03 RMI Interface
11:00 KSA
MEDIUM
CVSS 6.3
CWE-77
A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interface. Performing a manipulation of the argument troiaCode results in os command injection. The attack may be init…
CVE-2026-8774
Edimax BR-6228NC Command Injection in /goform/mp POST Handler
09:00 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack may be performed from remote. The explo…
CVE-2026-8777
Edimax BR-6428NS Command Injection via formStaDrvSetup POST Handler
09:00 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. Performing a manipulation of the argument stadrv_ssid results in command injection. The attack can be ini…
CVE-2026-8786
Tencent WeKnora Authorization Bypass in Config API (CVE-2026-8786)
11:36 KSA
MEDIUM
CVSS 6.3
CWE-285
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API Endpoint. The manipulation of the argument kbId leads to authorizatio…
CVE-2026-45231
DumbAssets Stored XSS in Asset Fields via Unsanitized Input
03:16 KSA
MEDIUM
CVSS 6.1
CWE-79
DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side sanitization and rendered using innerHTML without client-side escaping. Attackers ca…
CVE-2026-45243
Missing Authorization in Summarize Content Script Message Bridge
03:16 KSA
MEDIUM
CVSS 6.1
CWE-862
Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts. Attackers can simulate runtime messages with spoofed sender identifiers…
CVE-2026-41949
Dify Authorization Bypass in File Preview Endpoint (CVE-2026-41949)
22:26 KSA
MEDIUM
CVSS 5.9
CWE-639
Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access t…
CVE-2026-32849
NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/op
00:54 KSA
MEDIUM
CVSS 5.5
CWE-190
NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior w…
CVE-2026-45246
Insecure File Permissions in Summarize Configuration Rewrite
03:16 KSA
MEDIUM
CVSS 5.5
CWE-732
Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default filesystem permissions. When the refresh-free path rewrites the configuration fi…
CVE-2026-45244
Summarize Extension Missing Authorization in Browser Automation
03:16 KSA
MEDIUM
CVSS 5.4
CWE-862
Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation feature is enabled. Attackers can influence the agent through malicious page or summar…
CVE-2026-45492
Microsoft Edge Input Validation Bypass Security Feature Vulnerability
00:54 KSA
MEDIUM
CVSS 5.4
CWE-20
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-45494
Microsoft Edge Spoofing Vulnerability (CVE-2026-45494)
00:54 KSA
MEDIUM
CVSS 5.4
CWE-79
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-8767
Vercel AI OS Command Injection via PR Branch Name Interpolation
06:16 KSA
MEDIUM
CVSS 5.0
CWE-77
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The …