Vulnerabilities (CVE)

Total 403841 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26701 1 Jon-remus-sevellejo 1 Personnel Property Equipment System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php.
CVE-2026-26700 1 Jon-remus-sevellejo 1 Personnel Property Equipment System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php.
CVE-2026-26699 1 Jon-remus-sevellejo 1 Personnel Property Equipment System 2026-06-17 N/A 7.2 HIGH
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.
CVE-2026-26698 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 4.9 MEDIUM
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.
CVE-2026-26697 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 4.9 MEDIUM
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?teacherID=.
CVE-2026-26696 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.
CVE-2026-26695 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
CVE-2026-26694 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.
CVE-2026-26682 1 Xjd2020 1 Fastcms 2026-06-17 N/A 7.8 HIGH
An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java component
CVE-2026-26673 1 Dji 6 Mavic Mini, Mavic Mini Firmware, Mini Se and 3 more 2026-06-17 N/A 7.5 HIGH
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem
CVE-2026-26514 1 Xddxdd 1 Bird-lg-go 2026-06-17 N/A 7.5 HIGH
An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split to parse user input without validation, allowing remote attackers to inject arbitrary flags (e.g., -w, -q) via the q parameter. This can be exploited to cause a Denial of Service (DoS) by exhausting system resources.
CVE-2026-26478 1 Mobvoi 2 Tichome Mini, Tichome Mini Firmware 2026-06-17 N/A 9.8 CRITICAL
A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.
CVE-2026-26464 1 Kashipara 1 Society Management System Portal 2026-06-17 N/A 6.1 MEDIUM
Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that is executed in users' browsers. This vulnerability can be exploited via the name parameter in a POST HTTP request, leading to execution of malicious scripts when the affected content is viewed by other users, including administrators.
CVE-2026-26462 2026-06-17 N/A 7.3 HIGH
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary operating system commands.
CVE-2026-26461 2026-06-17 N/A 6.5 MEDIUM
A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web request.
CVE-2026-26460 2026-06-17 N/A 6.1 MEDIUM
A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to inject arbitrary HTML content into the dashboard interface. The injected content is rendered in the victim's browser
CVE-2026-26418 1 Tcs 1 Cognix Platform 2026-06-17 N/A 7.5 HIGH
Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network.
CVE-2026-26417 1 Tcs 1 Cognix Platform 2026-06-17 N/A 8.1 HIGH
A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests.
CVE-2026-26416 1 Tcs 1 Cognix Platform 2026-06-17 N/A 8.8 HIGH
An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate privileges across role boundaries via crafted requests.
CVE-2026-26399 2026-06-17 N/A 5.3 MEDIUM
A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to HAL initialization routines, where it is stored in a global timer handle registry. After the function returns, interrupt service routines may dereference this dangling pointer, resulting in memory corruption.