CVE-2021-47757
Last Modified: 5 Mar 2026Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the server.
CVE-2021-47755
Last Modified: 7 Apr 2026Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.
CVE-2021-47754
Last Modified: 7 Apr 2026Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.
CVE-2021-47753
Last Modified: 7 Apr 2026phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter.
CVE-2021-47752
Last Modified: 7 Apr 2026AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash or render the service unresponsive.
CVE-2025-61973
Last Modified: 15 Apr 2026A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.
CVE-2026-0897
Last Modified: 18 Apr 2026Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.
CVE-2026-0991
Last Modified: 23 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-13859
Last Modified: 15 Apr 2026The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_customization_settings AJAX action in versions 1.0.0 to 1.3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to store arbitrary JavaScript that executes whenever an AffiliateX block renders on the site.
CVE-2025-13062
Last Modified: 22 Apr 2026The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2025-12895
Last Modified: 22 Apr 2026The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the kalium_vc_contact_form_request() function in all versions up to, and including, 3.29. This makes it possible for unauthenticated attackers to use the theme an an open mail relay and send email to arbitrary email addresses on the server's behalf.
CVE-2026-22646
Last Modified: 18 Apr 2026Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.
CVE-2026-22645
Last Modified: 18 Apr 2026The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components.
CVE-2026-22644
Last Modified: 18 Apr 2026Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.
CVE-2026-22643
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22642
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22641
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22640
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22639
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22638
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22637
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-0713
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-0712
Last Modified: 22 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22920
Last Modified: 12 May 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22919
Last Modified: 18 Apr 2026An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.
CVE-2026-22918
Last Modified: 18 Apr 2026An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.
CVE-2026-22917
Last Modified: 18 Apr 2026Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.
CVE-2026-22916
Last Modified: 18 Apr 2026An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.
CVE-2026-22915
Last Modified: 18 Apr 2026An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.
CVE-2026-22914
Last Modified: 18 Apr 2026An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.
CVE-2026-22913
Last Modified: 18 Apr 2026Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.
CVE-2026-22912
Last Modified: 18 Apr 2026Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.
CVE-2026-22911
Last Modified: 18 Apr 2026Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.
CVE-2026-22910
Last Modified: 18 Apr 2026The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.
CVE-2026-22909
Last Modified: 18 Apr 2026Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.
CVE-2026-22908
Last Modified: 23 Jan 2026Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.
CVE-2026-23709
Last Modified: 16 Jan 2026Not used
CVE-2026-23710
Last Modified: 16 Jan 2026Not used
CVE-2026-23711
Last Modified: 16 Jan 2026Not used
CVE-2026-23712
Last Modified: 16 Jan 2026Not used
CVE-2026-23713
Last Modified: 16 Jan 2026Not used
CVE-2026-23714
Last Modified: 16 Jan 2026Not used
CVE-2026-22907
Last Modified: 18 Apr 2026An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.
CVE-2025-14457
Last Modified: 22 Apr 2026The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.
CVE-2025-14448
Last Modified: 21 Apr 2026The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-0988
Last Modified: 24 Apr 2026A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).
CVE-2025-67078
Last Modified: 10 Mar 2026Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.
CVE-2026-0992
Last Modified: 22 Apr 2026A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.
CVE-2026-0976
Last Modified: 18 Apr 2026A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable.
CVE-2025-70744
Last Modified: 20 Jan 2026Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
