Total
403846 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-26744 | 1 Formalms | 1 Formalms | 2026-06-17 | N/A | 5.3 MEDIUM |
| A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames allowing an unauthenticated attacker to determine which usernames are registered in the system through observable response discrepancy. | |||||
| CVE-2026-26742 | 1 Dronecode | 1 Px4 Drone Autopilot | 2026-06-17 | N/A | 8.1 HIGH |
| PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check. This allows for an immediate high-thrust takeoff if the throttle stick is raised, leading to loss of control. | |||||
| CVE-2026-26741 | 1 Dronecode | 1 Px4 Drone Autopilot | 2026-06-17 | N/A | 8.1 HIGH |
| PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" state (after landing and before the automatic disarm triggered by the COM_DISARM_LAND parameter), the system lacks a throttle threshold safety check for the physical throttle stick. This flaw can directly cause the drone to lose control, experience rapid uncontrolled ascent (flyaway), and result in property damage | |||||
| CVE-2026-26738 | 1 Uderzo | 1 Spacesniffer | 2026-06-17 | N/A | 7.8 HIGH |
| Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file. | |||||
| CVE-2026-26736 | 1 Totolink | 2 A3002ru-v3, A3002ru Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function. | |||||
| CVE-2026-26732 | 1 Totolink | 2 A3002ru-v2, A3002ru Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function. | |||||
| CVE-2026-26725 | 1 Edubusinesssolutions | 1 Print Shop Pro Webdesk | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID parameter. | |||||
| CVE-2026-26724 | 1 Keystorage | 1 Global Facilities Management Software | 2026-06-17 | N/A | 7.6 HIGH |
| Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the selectgroup and gn parameters on the /?Function=Groups endpoint. | |||||
| CVE-2026-26723 | 1 Keystorage | 1 Global Facilities Management Software | 2026-06-17 | N/A | 8.2 HIGH |
| Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter. | |||||
| CVE-2026-26722 | 1 Keystorage | 1 Global Facilities Management Software | 2026-06-17 | N/A | 9.4 CRITICAL |
| An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of the login functionality. | |||||
| CVE-2026-26721 | 1 Keystorage | 1 Global Facilities Management Software | 2026-06-17 | N/A | 7.1 HIGH |
| An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensitive information via the sid query parameter. | |||||
| CVE-2026-26720 | 1 Twenty | 1 Twenty | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module. | |||||
| CVE-2026-26717 | 2026-06-17 | N/A | 4.8 MEDIUM | ||
| An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies | |||||
| CVE-2026-26713 | 1 Carmelo | 1 Simple Food Order System | 2026-06-17 | N/A | 9.8 CRITICAL |
| code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php. | |||||
| CVE-2026-26712 | 1 Carmelo | 1 Simple Food Order System | 2026-06-17 | N/A | 9.8 CRITICAL |
| code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php. | |||||
| CVE-2026-26711 | 1 Carmelo | 1 Simple Food Order System | 2026-06-17 | N/A | 9.8 CRITICAL |
| code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php. | |||||
| CVE-2026-26710 | 1 Carmelo | 1 Simple Food Order System | 2026-06-17 | N/A | 9.8 CRITICAL |
| code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php. | |||||
| CVE-2026-26709 | 1 Carmelo | 1 Simple Gym Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php. | |||||
| CVE-2026-26708 | 1 Oretnom23 | 1 Pharmacy Point Of Sale System | 2026-06-17 | N/A | 9.8 CRITICAL |
| sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. | |||||
| CVE-2026-26707 | 1 Oretnom23 | 1 Pharmacy Point Of Sale System | 2026-06-17 | N/A | 9.8 CRITICAL |
| sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. | |||||
