7.7
    High

    CVE-2026-37149

    Last Modified: 26 Jun 2026

    GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

    Published:25 Jun 2026
    5.3
    Medium

    CVE-2026-37073

    Last Modified: 2 Sept 2026

    Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.

    Published:27 Aug 2026
    9.8
    Critical

    CVE-2026-37072

    Last Modified: 3 Sept 2026

    Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.

    Published:27 Aug 2026
    9.8
    Critical

    CVE-2026-37071

    Last Modified: 3 Sept 2026

    Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.

    Published:27 Aug 2026
    6.5
    Medium

    CVE-2026-37070

    Last Modified: 3 Sept 2026

    Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.

    Published:27 Aug 2026
    5.3
    Medium

    CVE-2026-37069

    Last Modified: 3 Sept 2026

    Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.

    Published:27 Aug 2026
    8.1
    High

    CVE-2026-37068

    Last Modified: 3 Sept 2026

    Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.

    Published:27 Aug 2026
    5.3
    Medium

    CVE-2026-37067

    Last Modified: 29 Aug 2026

    Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.

    Published:27 Aug 2026
    6.5
    Medium

    CVE-2026-37066

    Last Modified: 3 Sept 2026

    Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.

    Published:27 Aug 2026
    9.1
    Critical

    CVE-2026-37065

    Last Modified: 3 Sept 2026

    Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.

    Published:27 Aug 2026
    5.3
    Medium

    CVE-2026-37064

    Last Modified: 2 Sept 2026

    User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.

    Published:27 Aug 2026
    Unknown

    CVE-2026-36981

    https://github.com/canomer/CVE-2026-36981-Kernel-EoP-PoC

    Unknown

    CVE-2026-36980

    https://github.com/canomer/CVE-2026-36980-Kernel-BSOD-DoS-PoC

    8.8
    High

    CVE-2026-36960

    Last Modified: 2 May 2026

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.

    Published:30 Apr 2026
    7.5
    High

    CVE-2026-36959

    Last Modified: 5 May 2026

    U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized access to the router management interface.

    Published:30 Apr 2026
    7.5
    High

    CVE-2026-36958

    Last Modified: 5 May 2026

    A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the router web interface to become unresponsive and may require manual reboot to restore normal operation.

    Published:30 Apr 2026
    7.5
    High

    CVE-2026-36957

    Last Modified: 5 May 2026

    Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffers. This results in a kernel deadlock or system hang that disables the web management portal and all routing capabilities.

    Published:30 Apr 2026
    8.8
    High

    CVE-2026-36956

    Last Modified: 5 May 2026

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints such as /api/setWlan. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.

    Published:30 Apr 2026
    7.5
    High

    CVE-2026-36851

    Last Modified: 28 Aug 2026

    Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

    Published:26 Aug 2026
    7.5
    High

    CVE-2026-36848

    Last Modified: 1 Jul 2026

    Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

    Published:29 Jun 2026
    Unknown

    CVE-2026-36834

    https://github.com/kpatsakis/CVE-2026-36834

    Unknown

    CVE-2026-36826

    https://github.com/Forklit/CVE-2026-36826

    9
    Critical

    CVE-2026-36748

    Last Modified: 5 Jun 2026

    RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

    Published:3 Jun 2026
    8.8
    High

    CVE-2026-36670

    Last Modified: 26 Jun 2026

    A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php.

    Published:15 Jun 2026
    9.8
    Critical

    CVE-2026-36669

    Last Modified: 1 Aug 2026

    An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.

    Published:17 Jul 2026
    7.5
    High

    CVE-2026-36590

    Last Modified: 1 Aug 2026

    An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

    Published:15 Jul 2026
    Unknown

    CVE-2026-36522

    https://github.com/deepwoodssec/CVE-2026-36522

    5.3
    Medium

    CVE-2026-36438

    Last Modified: 19 May 2026

    An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd

    Published:18 May 2026
    Unknown

    CVE-2026-36436

    https://github.com/vtrmK/CVE-2026-36436-Public-Reference-Pack

    6.5
    Medium

    CVE-2026-36425

    Last Modified: 13 Aug 2026

    An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.

    Published:16 Jul 2026
    5.4
    Medium

    CVE-2026-36392

    Last Modified: 11 Sept 2026

    FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is stored server-side and executed in the browser of any client user who visits the store page, enabling session hijacking, account takeover, and phishing.

    Published:10 Sept 2026
    Unknown

    CVE-2026-36374

    https://github.com/RRespxwnss/CVE-2026-36374

    5.4
    Medium

    CVE-2026-36358

    Last Modified: 6 May 2026

    Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner Ads function

    Published:6 May 2026
    9.1
    Critical

    CVE-2026-36356

    Last Modified: 27 May 2026

    The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.

    Source:Daniil Gordeev
    Published:5 May 2026
    7.7
    High

    CVE-2026-36355

    Last Modified: 27 May 2026

    The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks on the write_mem (ioctl 0x89F5) and read_mem (ioctl 0x89F6) debug handlers, which are compiled into production builds via the unconditionally defined _IOCTL_DEBUG_CMD_ macro in 8192cd_cfg.h

    Source:Daniil Gordeev
    Published:5 May 2026
    5.4
    Medium

    CVE-2026-36341

    Last Modified: 7 May 2026

    Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint

    Published:7 May 2026
    8.1
    High

    CVE-2026-36340

    Last Modified: 2 May 2026

    An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

    Published:30 Apr 2026
    4.3
    Medium

    CVE-2026-36239

    Last Modified: 28 May 2026

    PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

    Published:26 May 2026
    7.3
    High

    CVE-2026-36228

    Last Modified: 25 May 2026

    Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality

    Published:22 May 2026
    6.5
    Medium

    CVE-2026-36227

    Last Modified: 25 May 2026

    Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter

    Published:22 May 2026
    6.1
    Medium

    CVE-2026-36226

    Last Modified: 22 May 2026

    Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component

    Published:22 May 2026
    6.4
    Medium

    CVE-2026-36214

    Last Modified: 5 Aug 2026

    osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or Admin sessions.

    Published:14 Jul 2026
    7.8
    High

    CVE-2026-36213

    Last Modified: 6 Jul 2026

    An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.

    Source:Mohammad
    Published:15 Jun 2026
    Unknown

    CVE-2026-36130

    https://github.com/cwjchoi01/CVE-2026-36130

    6.8
    Medium

    CVE-2026-36027

    Last Modified: 1 Aug 2026

    An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and Android Debug Bridge components

    Published:8 Jul 2026
    9.8
    Critical

    CVE-2026-35904

    Last Modified: 8 Jun 2026

    Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via sending a crafted request to a vulnerable CGI component.

    Published:4 Jun 2026
    Unknown

    CVE-2026-35678

    https://github.com/sharma19d/CVE-2026-35678

    9.1
    Critical

    CVE-2026-35616

    Last Modified: 18 Aug 2026

    A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

    Published:4 Apr 2026
    5.4
    Medium

    CVE-2026-35603

    Last Modified: 22 Apr 2026

    Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access permissions. Because the ProgramData directory is writable by non-administrative users by default and the ClaudeCode subdirectory was not pre-created or access-restricted, a low-privileged local user could create this directory and place a malicious configuration file that would be automatically loaded for any user launching Claude Code on the same machine. Exploiting this would have required a shared multi-user Windows system and a victim user to launch Claude Code after the malicious configuration was placed. This issue has been fixed on version 2.1.75.

    Published:17 Apr 2026
    7.5
    High

    CVE-2026-35585

    Last Modified: 9 Jun 2026

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 until 2.33.8, the hook system in File Browser — which executes administrator-defined shell commands on file events such as upload, rename, and delete — is vulnerable to OS command injection. Variable substitution for values like $FILE and $USERNAME is performed via os.Expand without sanitization. An attacker with file write permission can craft a malicious filename containing shell metacharacters, causing the server to execute arbitrary OS commands when the hook fires. This results in Remote Code Execution (RCE). This feature has been disabled by default for all installations from v2.33.8 onwards, including for existent installations.

    Published:7 Apr 2026
    Items Per Page