Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

33925
Total
2632
Critical
10022
High
10229
Medium
CVE ID Severity Score Description Published
CVE-2021-47960 MEDIUM 6.5 A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation … Apr 10, 2026
CVE-2026-6042 LOW 3.3 A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 … Apr 10, 2026
CVE-2026-6038 HIGH 7.3 A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argument … Apr 10, 2026
CVE-2026-6037 HIGH 7.3 A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument … Apr 10, 2026
CVE-2026-6036 HIGH 7.3 A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of … Apr 10, 2026
CVE-2026-33457 UNKNOWN Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted … Apr 10, 2026
CVE-2026-33456 UNKNOWN Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject … Apr 10, 2026
CVE-2026-33455 UNKNOWN Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input … Apr 10, 2026
CVE-2026-6035 MEDIUM 4.3 A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unknown function of the file /BranchManagement/ServiceAndSalesReport.php. The manipulation … Apr 10, 2026
CVE-2026-6034 MEDIUM 4.3 A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /BranchManagement/ProfitAndLossReport.php. Executing a manipulation of … Apr 10, 2026
CVE-2026-6033 MEDIUM 6.3 A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fname … Apr 10, 2026
CVE-2026-6032 MEDIUM 4.3 A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkcheckout.php. Performing a manipulation of the argument … Apr 10, 2026
CVE-2026-6031 HIGH 7.3 A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the file /add-category-function.php. Such manipulation of the … Apr 10, 2026
CVE-2026-5525 MEDIUM 6.0 A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path … Apr 10, 2026
CVE-2026-40212 MEDIUM 5.4 OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant … Apr 10, 2026
CVE-2026-22750 HIGH 7.5 When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was … Apr 10, 2026
CVE-2026-6030 MEDIUM 6.3 A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /del1.php. This manipulation of … Apr 10, 2026
CVE-2026-6029 CRITICAL 9.8 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The … Apr 10, 2026
CVE-2026-6028 CRITICAL 9.8 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The … Apr 10, 2026
CVE-2026-6027 CRITICAL 9.8 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing … Apr 10, 2026
CVE-2026-6026 CRITICAL 9.8 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. … Apr 10, 2026
CVE-2026-4432 MEDIUM 6.5 The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The … Apr 10, 2026
CVE-2026-28704 HIGH 7.8 Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed with … Apr 10, 2026
CVE-2026-1115 CRITICAL 9.6 A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in … Apr 10, 2026
CVE-2025-14545 MEDIUM 6.5 The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation process. Apr 10, 2026