Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
31688
Total
2494
Critical
9415
High
9684
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-6167 | HIGH | 7.3 | A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file /subject-print.php. The manipulation of the argument ID … | Apr 13, 2026 |
| CVE-2026-6166 | HIGH | 7.3 | A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/UpdateVehicleFunction.php. The manipulation … | Apr 13, 2026 |
| CVE-2026-5936 | HIGH | 8.5 | An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may … | Apr 13, 2026 |
| CVE-2026-5085 | CRITICAL | 9.1 | Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash … | Apr 13, 2026 |
| CVE-2026-40436 | HIGH | 7.1 | The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access … | Apr 13, 2026 |
| CVE-2026-3830 | HIGH | 8.6 | The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, … | Apr 13, 2026 |
| CVE-2026-34866 | MEDIUM | 5.1 | Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | Apr 13, 2026 |
| CVE-2026-34865 | UNKNOWN | — | Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | Apr 13, 2026 |
| CVE-2025-15441 | MEDIUM | 6.8 | The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could … | Apr 13, 2026 |
| CVE-2026-6165 | HIGH | 7.3 | A weakness has been identified in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/Login_check.php. Executing a manipulation of … | Apr 13, 2026 |
| CVE-2026-6164 | HIGH | 7.3 | A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Performing a … | Apr 13, 2026 |
| CVE-2026-6163 | HIGH | 7.3 | A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file /catageory.php. Such … | Apr 13, 2026 |
| CVE-2026-40447 | MEDIUM | 5.1 | Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. | Apr 13, 2026 |
| CVE-2026-21014 | UNKNOWN | — | Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability. | Apr 13, 2026 |
| CVE-2026-21013 | UNKNOWN | — | Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information. | Apr 13, 2026 |
| CVE-2026-21012 | LOW | 3.3 | External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege. | Apr 13, 2026 |
| CVE-2026-21011 | MEDIUM | 6.8 | Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock. | Apr 13, 2026 |
| CVE-2026-21010 | MEDIUM | 6.6 | Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions. | Apr 13, 2026 |
| CVE-2026-21009 | UNKNOWN | — | Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning. | Apr 13, 2026 |
| CVE-2026-21008 | MEDIUM | 6.5 | Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information. | Apr 13, 2026 |
| CVE-2026-21007 | MEDIUM | 6.8 | Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard. | Apr 13, 2026 |
| CVE-2026-21006 | LOW | 2.4 | Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents. | Apr 13, 2026 |
| CVE-2026-6162 | LOW | 3.5 | A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of the file /bwdates-reports-details.php. The manipulation of the … | Apr 13, 2026 |
| CVE-2026-6161 | HIGH | 7.3 | A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the component Endpoint. Executing … | Apr 13, 2026 |
| CVE-2026-6160 | MEDIUM | 5.3 | A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. … | Apr 13, 2026 |