CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2026-20445

    Last Modified: 16 Apr 2026

    In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10289875; Issue ID: MSV-5184.

    Published: 2 Mar 2026
    4.4
    Medium

    CVE-2026-20429

    Last Modified: 16 Apr 2026

    In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5535.

    Published: 2 Mar 2026
    4.4
    Medium

    CVE-2026-20424

    Last Modified: 16 Apr 2026

    In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5540.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20444

    Last Modified: 16 Apr 2026

    In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436995; Issue ID: MSV-5721.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20443

    Last Modified: 16 Apr 2026

    In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436998; Issue ID: MSV-5722.

    Published: 2 Mar 2026
    4.4
    Medium

    CVE-2026-20442

    Last Modified: 16 Apr 2026

    In display, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436998; Issue ID: MSV-5723.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20441

    Last Modified: 16 Apr 2026

    In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10432500; Issue ID: MSV-5803.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20440

    Last Modified: 16 Apr 2026

    In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431968; Issue ID: MSV-5824.

    Published: 2 Mar 2026
    4.4
    Medium

    CVE-2026-20439

    Last Modified: 16 Apr 2026

    In imgsys, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431955; Issue ID: MSV-5826.

    Published: 2 Mar 2026
    6.4
    Medium

    CVE-2026-20438

    Last Modified: 16 Apr 2026

    In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431920; Issue ID: MSV-5835.

    Published: 2 Mar 2026
    4.4
    Medium

    CVE-2026-20437

    Last Modified: 16 Apr 2026

    In MAE, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431940; Issue ID: MSV-5843.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20436

    Last Modified: 16 Apr 2026

    In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00473802; Issue ID: MSV-5970.

    Published: 2 Mar 2026
    4.6
    Medium

    CVE-2026-20435

    Last Modified: 16 Apr 2026

    In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID: MSV-6118.

    Published: 2 Mar 2026
    7.5
    High

    CVE-2026-20434

    Last Modified: 16 Apr 2026

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY00782946; Issue ID: MSV-4135.

    Published: 2 Mar 2026
    8.8
    High

    CVE-2026-20430

    Last Modified: 16 Apr 2026

    In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00467553; Issue ID: MSV-5151.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20428

    Last Modified: 16 Apr 2026

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5536.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20427

    Last Modified: 16 Apr 2026

    In display, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5537.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20426

    Last Modified: 16 Apr 2026

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5538.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-20425

    Last Modified: 16 Apr 2026

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5539.

    Published: 2 Mar 2026
    7.8
    High

    CVE-2026-20423

    Last Modified: 16 Apr 2026

    In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465314; Issue ID: MSV-4956.

    Published: 2 Mar 2026
    9.3
    Critical

    CVE-2026-3422

    Last Modified: 16 Apr 2026

    U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

    Published: 2 Mar 2026
    2.1
    Low

    CVE-2025-15597

    Last Modified: 5 Mar 2026

    A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.0 mitigates this issue. The name of the patch is d640ac31d1ce64ce90e06cf7081163915c9fc28c. Upgrading the affected component is recommended. Multiple endpoints are affected. The vendor was contacted early about this disclosure.

    Published: 2 Mar 2026
    9.3
    Critical

    CVE-2026-3000

    Last Modified: 16 Apr 2026

    IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.

    Published: 2 Mar 2026
    5.5
    Medium

    CVE-2026-3413

    Last Modified: 18 Apr 2026

    A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

    Published: 2 Mar 2026
    9.3
    Critical

    CVE-2026-2999

    Last Modified: 16 Apr 2026

    IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

    Published: 2 Mar 2026
    2.1
    Low

    CVE-2026-3412

    Last Modified: 16 Apr 2026

    A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file /att_single_view.php. The manipulation of the argument dt results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.

    Published: 2 Mar 2026
    5.5
    Medium

    CVE-2026-3411

    Last Modified: 17 Apr 2026

    A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /admin_single_student_update.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

    Published: 2 Mar 2026
    5.5
    Medium

    CVE-2026-3410

    Last Modified: 17 Apr 2026

    A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/check_studid.php. Executing a manipulation of the argument student_id can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 2 Mar 2026
    5.5
    Medium

    CVE-2026-3409

    Last Modified: 22 Apr 2026

    A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import Endpoint. Performing a manipulation as part of File results in code injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2026
    2.1
    Low

    CVE-2026-3408

    Last Modified: 17 Apr 2026

    A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit is publicly available and might be used. The name of the patch is e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. It is best practice to apply a patch to resolve this issue.

    Published: 2 Mar 2026
    1.9
    Low

    CVE-2026-3407

    Last Modified: 22 Apr 2026

    A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Applying a patch is the recommended action to fix this issue. It appears that the issue is not reproducible all the time.

    Published: 2 Mar 2026
    5.5
    Medium

    CVE-2026-3406

    Last Modified: 17 Apr 2026

    A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

    Published: 2 Mar 2026
    1.3
    Low

    CVE-2026-3405

    Last Modified: 16 Apr 2026

    A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2026
    1.3
    Low

    CVE-2026-3404

    Last Modified: 16 Apr 2026

    A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2026
    1.9
    Low

    CVE-2026-3403

    Last Modified: 16 Apr 2026

    A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

    Published: 2 Mar 2026
    1.9
    Low

    CVE-2026-3402

    Last Modified: 17 Apr 2026

    A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

    Published: 2 Mar 2026
    1.3
    Low

    CVE-2026-3401

    Last Modified: 16 Apr 2026

    A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks.

    Published: 2 Mar 2026
    4.2
    Medium

    CVE-2026-3429

    Last Modified: 18 Aug 2026

    A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-24105

    Last Modified: 17 Apr 2026

    An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-26709

    Last Modified: 17 Apr 2026

    code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-26695

    Last Modified: 17 Apr 2026

    code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-26705

    Last Modified: 17 Apr 2026

    sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-26704

    Last Modified: 17 Apr 2026

    sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-26711

    Last Modified: 16 Apr 2026

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-26708

    Last Modified: 17 Apr 2026

    sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-24108

    Last Modified: 17 Apr 2026

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a buffer overflow vulnerability.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-26713

    Last Modified: 16 Apr 2026

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-26710

    Last Modified: 16 Apr 2026

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.

    Published: 2 Mar 2026
    4.9
    Medium

    CVE-2026-26697

    Last Modified: 16 Apr 2026

    code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?teacherID=.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-24111

    Last Modified: 18 Apr 2026

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addAuthUser` function and processed by `sscanf` without size validation, it could lead to buffer overflow.

    Published: 2 Mar 2026