Total
396904 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-86225 | 2026-09-08 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. | |||||
| CVE-2026-86220 | 2026-09-08 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. | |||||
| CVE-2026-86179 | 2026-09-08 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used. | |||||
| CVE-2026-86168 | 2026-09-08 | 7.5 HIGH | 7.3 HIGH | ||
| A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | |||||
| CVE-2026-86167 | 2026-09-08 | 9.0 HIGH | 9.9 CRITICAL | ||
| A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |||||
| CVE-2026-86163 | 2026-09-08 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. | |||||
| CVE-2026-86153 | 2026-09-08 | 8.3 HIGH | 9.1 CRITICAL | ||
| A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible. | |||||
| CVE-2026-86148 | 2026-09-08 | 8.3 HIGH | 9.1 CRITICAL | ||
| A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely. | |||||
| CVE-2026-86121 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication. | |||||
| CVE-2026-86116 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization. | |||||
| CVE-2026-86095 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names. | |||||
| CVE-2026-85701 | 2026-09-08 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-85699 | 2026-09-08 | N/A | 7.5 HIGH | ||
| jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata endpoints, allowing the server to fetch and return the target's response body to the attacker. | |||||
| CVE-2026-85643 | 2026-09-08 | 5.8 MEDIUM | 4.7 MEDIUM | ||
| A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |||||
| CVE-2026-85636 | 2026-09-08 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-62886 | 1 Microsoft | 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more | 2026-09-08 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |||||
| CVE-2026-46636 | 2026-09-08 | N/A | N/A | ||
| Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0. | |||||
| CVE-2026-17057 | 1 Ibm | 1 I | 2026-09-08 | N/A | 6.5 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions. | |||||
| CVE-2026-16689 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-08 | N/A | 6.2 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials. | |||||
| CVE-2026-13297 | 2026-09-08 | N/A | 7.5 HIGH | ||
| IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack. | |||||
