Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-94003 | CRITICAL | 10.0 | A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The … | Sep 20, 2026 |
| CVE-2026-93997 | HIGH | 7.3 | A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation … | Sep 20, 2026 |
| CVE-2026-93980 | HIGH | 7.3 | A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login … | Sep 20, 2026 |
| CVE-2026-93979 | HIGH | 7.3 | A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of … | Sep 20, 2026 |
| CVE-2026-93978 | HIGH | 7.3 | A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of … | Sep 20, 2026 |
| CVE-2026-93977 | LOW | 3.5 | A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the … | Sep 20, 2026 |
| CVE-2026-93976 | LOW | 2.4 | A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results … | Sep 20, 2026 |
| CVE-2026-93975 | LOW | 2.4 | A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The … | Sep 20, 2026 |
| CVE-2026-86555 | MEDIUM | 6.2 | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the … | Sep 20, 2026 |
| CVE-2026-93974 | HIGH | 7.3 | A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of … | Sep 20, 2026 |
| CVE-2026-93973 | HIGH | 7.3 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation … | Sep 20, 2026 |
| CVE-2026-93972 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such … | Sep 20, 2026 |
| CVE-2026-93971 | MEDIUM | 5.3 | A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is … | Sep 20, 2026 |
| CVE-2026-93970 | HIGH | 7.3 | A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. … | Sep 20, 2026 |
| CVE-2026-86554 | MEDIUM | 4.3 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the … | Sep 20, 2026 |
| CVE-2026-93969 | HIGH | 7.3 | A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The … | Sep 20, 2026 |
| CVE-2026-93968 | LOW | 3.8 | A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can … | Sep 20, 2026 |
| CVE-2026-93967 | MEDIUM | 5.5 | A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. … | Sep 20, 2026 |
| CVE-2026-93966 | MEDIUM | 4.7 | A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. … | Sep 20, 2026 |
| CVE-2026-92965 | LOW | 3.7 | The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so … | Sep 20, 2026 |
| CVE-2026-92541 | HIGH | 7.2 | The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with … | Sep 20, 2026 |
| CVE-2026-92540 | HIGH | 7.2 | The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, … | Sep 20, 2026 |
| CVE-2026-92423 | LOW | 2.7 | The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning … | Sep 20, 2026 |
| CVE-2026-92422 | MEDIUM | 6.5 | The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to … | Sep 20, 2026 |
| CVE-2026-92410 | MEDIUM | 4.3 | The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up … | Sep 20, 2026 |