By severity
Medium-severity vulnerabilities
CVEs rated Medium by CVSS, with SEC.co remediation and prioritization guidance.
4010 published vulnerabilities · page 12 of 41
- CVE-2026-10194MEDIUM 6.3
A heap-based buffer overflow exists in OFFIS DCMTK 3.7.0 within the query/retrieve service component (dcmqrscp). An authenticated attacker can trigger this flaw remotely by sending specially crafted requests to the image deletion function, potentially causing memory corruption, data loss, or service disruption. The vulnerability requires valid credentials to exploit but poses moderate risk in networked medical imaging environments where DCMTK is deployed.
- CVE-2026-10202MEDIUM 6.3
A SQL injection vulnerability exists in OFCMS version 1.1.3 affecting the JSON Query Interface within the SystemDictController component. An authenticated attacker can send specially crafted queries to manipulate SQL commands executed by the application, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials but can be exploited over the network without user interaction. Exploit code is publicly available, increasing the risk of active exploitation.
- CVE-2026-10203MEDIUM 6.3
A SQL injection vulnerability exists in OFCMS 1.1.3 within the Query function of the SystemParamController component. The flaw allows authenticated attackers to inject malicious SQL commands through the JSON Query Interface, potentially compromising database integrity and confidentiality. Public exploit code is available, increasing active exploitation risk.
- CVE-2026-10204MEDIUM 6.3
A SQL injection vulnerability has been discovered in OFCMS version 1.1.3, specifically in the JSON Query Interface of the user management controller. An authenticated attacker can submit specially crafted queries to execute arbitrary SQL commands against the application's database. This could allow them to read, modify, or delete sensitive data. The vulnerability is not currently on the CISA Known Exploited Vulnerabilities (KEV) catalog, but exploit code has been publicly released, increasing the practical risk of attacks.
- CVE-2026-10205MEDIUM 6.3
Metasoft MetaCRM version 6.4.0 contains an unrestricted file upload vulnerability in its logo upload functionality. An authenticated attacker can upload arbitrary files to the server, potentially leading to code execution or system compromise. The vulnerability affects a JSP file handling logo uploads and requires valid user credentials to exploit. Public exploit code exists for this issue.
- CVE-2026-10209MEDIUM 6.3
A SQL injection vulnerability exists in the Online Hospital Management System version 1.0, specifically in the appointment booking functionality. An authenticated attacker can manipulate the 'editid' parameter in the appointmentdetail.php file to inject malicious SQL commands. This allows an attacker with valid credentials to read, modify, or delete sensitive appointment and patient data without additional authorization. Since the exploit has been publicly disclosed, the risk of active exploitation is elevated.
- CVE-2026-10210MEDIUM 6.3
AstrBot version 4.23.6 contains a vulnerability in its skill management system that allows authenticated users to inject malicious code through the prompt description field. An attacker with login credentials can manipulate how skill prompts are processed, potentially leading to unauthorized data access, system modification, or service disruption. The vulnerability has been publicly disclosed, and exploit code is available, though the vendor has not engaged with disclosure efforts.
- CVE-2026-10211MEDIUM 6.3
AstrBot version 4.23.6 contains a flaw in how it validates file system paths, allowing authenticated users to bypass access restrictions and read, modify, or delete files they shouldn't be able to access. An attacker with valid credentials can exploit this remotely without user interaction. The vulnerability has already been disclosed publicly, and exploit code may be available.
- CVE-2026-10212MEDIUM 6.3
A flaw in AstrBot version 4.24.2 allows an authenticated attacker to manipulate the session_id parameter in the astr_main_agent function, bypassing authorization checks. This means a logged-in user could potentially access or modify resources belonging to other users or perform actions they should not be permitted to perform. The vulnerability is remotely exploitable and public exploits are available.
- CVE-2026-10217MEDIUM 6.3
A privilege management flaw exists in nextlevelbuilder GoClaw versions up to 3.11.3 that allows authenticated users to escalate their access or perform unauthorized actions. The vulnerability affects the RoleAdmin Gateway component, specifically in how it handles configuration saves. An attacker with valid credentials can exploit this remotely to gain elevated permissions or manipulate role-based access controls, potentially affecting data confidentiality, integrity, and availability.
- CVE-2026-10223MEDIUM 6.3
NousResearch's hermes-agent software contains an injection vulnerability in its memory scanning tool that allows authenticated users to inject malicious input. An attacker with valid credentials can exploit this flaw remotely to manipulate the application's memory handling logic. The vulnerability affects all versions up to 2026.4.30, and exploit code has already been publicly disclosed, raising the practical risk despite a moderate CVSS score.
- CVE-2026-10235MEDIUM 6.3
CodeAstro Ingredients Stock Management System version 1.0 contains a SQL injection vulnerability in its stock manager component. An authenticated attacker can manipulate the txt_search_category parameter in the /Ingredients-Stock/stock_manager.php file to execute arbitrary SQL queries. This allows unauthorized data access, modification, or deletion within the application's database. The vulnerability requires valid login credentials but can be exploited over the network without user interaction.
- CVE-2026-10239MEDIUM 6.3
JeecgBoot, an open-source low-code application development platform, contains a server-side request forgery (SSRF) vulnerability in its word document editing module. Specifically, the `WordUtil.addImage` function in the `/airag/word/edit` endpoint fails to properly validate image URLs, allowing an authenticated attacker to manipulate the application into making arbitrary HTTP requests on behalf of the server. This could expose internal resources, bypass firewalls, or facilitate lateral movement within a network. The vulnerability affects JeecgBoot versions up to and including 3.9.2 and has been publicly disclosed.
- CVE-2026-10240MEDIUM 6.3
JeecgBoot versions up to 3.9.2 contain a server-side request forgery (SSRF) vulnerability in the /airag/airagModel/test endpoint. An authenticated attacker can manipulate the baseUrl parameter to make the server perform unintended HTTP requests to internal or external systems. The vulnerability requires login credentials but does not require user interaction, and can be exploited over the network. A fix is planned for an upcoming release.
- CVE-2026-10241MEDIUM 6.3
JimuReport (jeecgboot) versions up to 3.9.1 contain a server-side request forgery (SSRF) vulnerability in a file download function exposed via a debug endpoint. An authenticated attacker can manipulate the application into making arbitrary network requests on behalf of the server, potentially accessing internal resources, cloud metadata, or other services not directly exposed to the internet. The vulnerability is reachable over the network and exploit code is publicly available.
- CVE-2026-10242MEDIUM 6.3
itsourcecode Content Management System version 1.0 contains a SQL injection vulnerability in the /instructions.php file. An attacker with user-level access can manipulate the topic_id parameter to execute unauthorized database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is remotely exploitable and public exploit code is available.
- CVE-2026-10256MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Content Management System version 1.0 affecting the comment-saving functionality. An authenticated attacker can manipulate the Name parameter in /save_comment.php to execute arbitrary SQL queries, potentially reading, modifying, or deleting database contents. The vulnerability requires valid user credentials but does not require user interaction to exploit. Public exploit code is available, elevating the practical risk despite the MEDIUM CVSS score.
- CVE-2026-10257MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Content Management System version 1.0, specifically in the admin update functionality. An authenticated user can inject malicious SQL commands through the topic_id parameter when uploading images, potentially reading, modifying, or deleting database contents. Public exploit code is available, increasing near-term risk.
- CVE-2026-10258MEDIUM 6.3
itsourcecode Content Management System version 1.0 contains a SQL injection vulnerability in its administrative interface. An authenticated attacker can manipulate the topic_id parameter in the /admin/add_sub_topic.php file to inject malicious SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. The vulnerability requires valid login credentials but can be exploited over the network without additional user interaction.
- CVE-2026-10265MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Content Management System version 1.0 that allows authenticated users to manipulate the topic_id parameter in the /admin/edit_topic.php file to execute arbitrary SQL queries. An attacker with valid admin credentials can exploit this to read, modify, or delete database records. Public exploits are available, elevating operational risk.
- CVE-2026-10269MEDIUM 6.3
A vulnerability in decolua 9router allows an authenticated user to bypass authorization controls by manipulating the Host HTTP header. The flaw exists in the authentication logic of the dashboard guard component and can be exploited remotely by someone with valid login credentials. Affected versions up to 0.4.0 should be updated immediately to 0.4.1.
- CVE-2026-10271MEDIUM 6.3
A flaw in a4m4 Student-Management-System allows an attacker to manipulate a parameter in the admin endpoint, causing the application to execute code after a redirect. The vulnerability requires user interaction but can be triggered remotely. An exploit has already been published publicly, increasing risk. The vendor uses rolling releases without traditional version numbers, making tracking more difficult for defenders.
- CVE-2026-10274MEDIUM 6.3
A server-side request forgery (SSRF) vulnerability exists in the aem-mcp-server project maintained by indrasishbanerjee. The flaw is in the getAssetMetadata function, which processes an assetPath parameter without proper validation. An authenticated attacker can manipulate this parameter to cause the server to make unintended HTTP requests to internal or external systems, potentially accessing sensitive data or interacting with restricted resources. The vulnerability is publicly known and exploit code may be in circulation.
- CVE-2026-10276MEDIUM 6.3
A server-side request forgery (SSRF) vulnerability exists in Jenkins-server-mcp version 0.1.0, a Jenkins integration tool. An authenticated attacker can manipulate the jobPath parameter in build status, log retrieval, or build trigger operations to make the server issue malicious requests to internal or external systems. The vulnerability requires valid login credentials but no user interaction, and the exploit code has already been made public.
- CVE-2026-10277MEDIUM 6.3
A security flaw exists in the MCP Google Workspace integration's Gmail tool that allows authenticated users to bypass access controls and manipulate file storage operations. An attacker with valid login credentials can remotely exploit this vulnerability to gain unauthorized access to data or perform unintended modifications. The vulnerability affects the component up to commit 831790e7d5c2663325733d9f5579cc339a267c4c, and a patch has been released.
- CVE-2026-10278MEDIUM 6.3
A path traversal vulnerability exists in the excel-mcp project (versions up to 1.0.2) that allows authenticated users to access files and directories outside the intended scope by manipulating file path parameters. An attacker with valid credentials can read or write files on the affected system by crafting malicious file path arguments, potentially exposing sensitive data or modifying system files. The vulnerability has been publicly disclosed, increasing the risk of active exploitation.
- CVE-2026-10279MEDIUM 6.3
A remote command injection vulnerability exists in wezterm-mcp version 0.1.0, a WezTerm terminal multiplexer control plane component. An authenticated attacker can manipulate the pane_id parameter in requests to the switch_pane/write_to_specific_pane function to inject arbitrary operating system commands. The vulnerability requires valid credentials to exploit but poses a meaningful risk in environments where WezTerm MCP is exposed to untrusted users or networked clients.
- CVE-2026-10283MEDIUM 6.3
Bottelet DaybydayCRM contains an authentication bypass vulnerability in its Settings Handler component. An authenticated attacker can manipulate application settings to gain unauthorized access to functionality they should not have, potentially viewing sensitive data, modifying records, or disrupting service availability. The vulnerability affects versions up to 2.2.1 and requires an attacker to already have valid login credentials to exploit it.
- CVE-2026-10286MEDIUM 6.3
CodeAstro Payroll System version 1.0 contains a SQL injection vulnerability in its employee home page functionality. An authenticated attacker can inject malicious SQL commands through the emp_id parameter, allowing them to read, modify, or delete database records. This vulnerability requires valid login credentials and is reachable over the network. Public exploit information is available, increasing the immediate risk of exploitation.
- CVE-2026-10296MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 that allows authenticated users to manipulate the Username parameter in the /ajax.php endpoint to execute arbitrary SQL queries. An attacker with valid login credentials can exploit this flaw to read, modify, or delete database contents. The vulnerability requires authentication but is otherwise straightforward to exploit and has been publicly disclosed.
- CVE-2026-10297MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 within the course management functionality. An authenticated attacker can manipulate the ID parameter in the /manage_course.php endpoint to execute arbitrary SQL queries against the underlying database. The vulnerability requires valid login credentials but can be exploited over the network without additional interaction. Exploit code is publicly available, elevating the practical risk.
- CVE-2026-10302MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 within the /manage_fee.php file. An authenticated attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. The vulnerability requires valid user credentials to exploit but can be triggered remotely over the network.
- CVE-2026-10550MEDIUM 6.3
A command injection vulnerability exists in elunez eladmin versions up to 2.7 within the Application Deployment Module. An authenticated user can manipulate the uploadPath argument to inject arbitrary commands, leading to remote code execution on the affected system. The vulnerability requires valid credentials to exploit but does not need user interaction once authenticated. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-10558MEDIUM 6.3
SourceCodester Pizzafy Ecommerce System version 1.0 contains a file inclusion vulnerability in its administrative interface. An attacker with valid login credentials can manipulate the 'page' parameter in /admin/index.php to include and execute arbitrary files on the server. This allows an authenticated attacker to read sensitive files, modify system behavior, or potentially execute code. The vulnerability is publicly known and proof-of-concept code is available.
- CVE-2026-10559MEDIUM 6.3
SourceCodester Pizzafy Ecommerce System version 1.0 contains a file inclusion vulnerability in its index.php file. An authenticated attacker can manipulate the 'page' parameter to include arbitrary files, potentially exposing sensitive data or executing unintended code. The vulnerability requires valid credentials but can be exploited over the network without user interaction.
- CVE-2026-10568MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the /manage_payment.php file to execute arbitrary SQL queries against the backend database. This vulnerability requires valid login credentials to exploit, but can lead to unauthorized data access, modification, or deletion. Public exploit code is available, increasing the practical risk of exploitation.
- CVE-2026-10581MEDIUM 6.3
DedeCMS 5.7.88 contains a server-side request forgery (SSRF) vulnerability in its download functionality. An authenticated attacker can manipulate the Link parameter passed to the base64_decode function in /plus/download.php to cause the server to make unintended requests to internal or external systems. This allows an attacker with login credentials to potentially access restricted resources, exfiltrate data, or pivot to other systems on the network.
- CVE-2026-10635MEDIUM 6.3
CVE-2026-10635 is a use-after-free vulnerability in Zephyr's Xtensa memory domain handling. When a memory domain is destroyed on Xtensa systems with MMU support, the kernel fails to cleanly remove the domain from an internal tracking list, leaving a dangling pointer. If the freed memory is later reused or accessed, kernel code can dereference corrupted data structures, potentially compromising memory isolation between privileged and unprivileged code. The vulnerability requires privileged kernel access to trigger and cannot be exploited directly from user space or remotely.
- CVE-2026-10662MEDIUM 6.3
A server-side request forgery (SSRF) vulnerability exists in ahujasid blender-mcp, a tool that handles ZIP file operations. An authenticated attacker can manipulate the ZIP file URL parameter to force the server to make HTTP requests to arbitrary internal or external systems. This could allow an attacker to access sensitive internal services, exfiltrate data, or pivot deeper into a network. The vulnerability affects versions up to commit 7636d13, and a patch is available.
- CVE-2026-10690MEDIUM 6.3
A server-side request forgery (SSRF) vulnerability exists in DesktopCommanderMCP version 0.2.37. The flaw allows authenticated attackers to manipulate URL parameters passed to the read_file function, enabling the server to make arbitrary HTTP requests on behalf of the attacker. This could expose internal services, exfiltrate data, or compromise systems that trust the affected server.
- CVE-2026-10693MEDIUM 6.3
SourceCodester Online Boat Reservation System version 1.0 contains a flaw in its administrative endpoints that fails to properly verify user permissions. An authenticated attacker can exploit this improper authorization to access or modify administrative functions they shouldn't have access to. The vulnerability requires an existing user account but can be exploited over the network without user interaction. The flaw affects multiple administrative endpoints, and exploit details have been publicly disclosed.
- CVE-2026-10703MEDIUM 6.3
A use-after-free memory safety flaw exists in EIPStackGroup OpENer versions up to 2.3.0 within the SendRRData request handler. An authenticated attacker can remotely trigger memory corruption by crafting malicious messages, potentially leading to information disclosure or service disruption. The vulnerability has been publicly disclosed but the vendor has not yet acknowledged or released a patch.
- CVE-2026-10806MEDIUM 6.3
CVE-2026-10806 is a medium-severity file upload vulnerability in mjperpinosa stumasy affecting the add_post.php component. An authenticated attacker can manipulate the up_file_to_post parameter to upload files without proper restrictions, potentially allowing arbitrary file placement on the server. The vulnerability requires valid login credentials but can be exploited over the network. Exploit code has been publicly disclosed, increasing practical risk.
- CVE-2026-10807MEDIUM 6.3
A file upload vulnerability exists in mjperpinosa stumasy that allows authenticated users to upload files without proper validation. By manipulating the profile image upload parameter in the application's profile management component, an attacker with login credentials can bypass upload restrictions and place arbitrary files on the server. The vulnerability requires authentication but poses meaningful risk to confidentiality, integrity, and availability of the affected system.
- CVE-2026-10808MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 that allows authenticated users to manipulate the ID parameter in the /manage_student.php file, potentially enabling unauthorized data access, modification, or deletion. The vulnerability requires valid login credentials but can be exploited remotely over the network. Public exploit code is available, elevating the risk of active attack.
- CVE-2026-10809MEDIUM 6.3
CVE-2026-10809 is a SQL injection vulnerability in itsourcecode Fees Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the /manage_user.php file to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The flaw requires valid login credentials but can be exploited over the network without user interaction. Public exploit code is available, elevating the practical risk despite the medium CVSS score.
- CVE-2026-10811MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0. The flaw resides in the /receipt.php file, specifically in how the application processes the ef_id parameter. An authenticated attacker can manipulate this parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete database records. Public disclosure of this vulnerability means exploitation techniques are already available, elevating the practical risk.
- CVE-2026-10815MEDIUM 6.3
A missing authorization vulnerability was discovered in the Hostel Management System PHP application, specifically in the Admin Dashboard Page's index.php file. An authenticated attacker can manipulate the ID parameter to bypass authorization checks, potentially gaining unauthorized access to sensitive administrative functions. The vulnerability requires valid login credentials but does not require user interaction once authenticated. Public exploit code is available, increasing the practical risk.
- CVE-2026-10874MEDIUM 6.3
A SQL injection vulnerability exists in projectworlds Online Art Gallery Shop Project version 1.0 affecting the admin dashboard. An authenticated attacker can manipulate the 'social_insta' parameter in the /admin/adminHome.php file to inject malicious SQL commands. This allows unauthorized access to sensitive database information, modification of data, or potential system disruption. The vulnerability requires valid login credentials but has no other technical barriers to exploitation.
- CVE-2026-10875MEDIUM 6.3
A SQL injection vulnerability exists in projectworlds Online Art Gallery Shop Project version 1.0 that allows authenticated users to inject malicious SQL commands through the social_twitter parameter in the admin panel. An attacker with login credentials can exploit this flaw to read, modify, or delete database records. Public exploit code has been released, increasing the risk of active exploitation.
- CVE-2026-10876MEDIUM 6.3
SourceCodester Ship Ferry Ticket Reservation System version 1.0 contains an authorization bypass vulnerability affecting its admin panel. An authenticated user can manipulate the 'page' parameter in requests to /admin/ to access functions they should not be permitted to use. This vulnerability requires valid login credentials to exploit, but once authenticated, an attacker can view, modify, or delete unauthorized data. The vulnerability has been publicly disclosed with working exploits available, increasing active risk.
- CVE-2026-10878MEDIUM 6.3
A command injection vulnerability has been discovered in D-Link DWR-M920 routers running firmware versions 1.1.50 and 1.1.70. An authenticated attacker can manipulate a parameter in the SMS management interface to inject and execute arbitrary system commands. This requires an existing login to the device but does not require user interaction once authenticated. Public exploits are now available, increasing the practical risk.
- CVE-2026-11181MEDIUM 6.3
Google Chrome versions before 149.0.7827.53 contain a flaw in how the Media Session feature is implemented. An attacker can craft a malicious HTML page that, when visited by a user, bypasses the browser's same-origin policy—a fundamental security boundary that prevents websites from accessing data or functionality from other sites without permission. This could allow the attacker to read sensitive information, make unauthorized changes, or disrupt functionality within the context of other websites the user has open. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require any special browser configuration.
- CVE-2026-11184MEDIUM 6.3
Google Chrome versions before 149.0.7827.53 contain a flaw that allows attackers to bypass navigation controls through a specially crafted webpage. An attacker could craft a malicious HTML page that, when visited by a user, circumvents Chrome's built-in protections that normally restrict where the browser can navigate. This requires user interaction—the victim must visit the malicious page—but the barrier to exploitation is otherwise low. The vulnerability affects Chrome on Windows, macOS, and Linux systems.
- CVE-2026-11187MEDIUM 6.3
Google Chrome versions prior to 149.0.7827.53 contain a flaw in the Glic component that allows an attacker to bypass navigation restrictions by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting the malicious page) and affects users across Windows, macOS, and Linux platforms. While the immediate impact is moderate, the ability to circumvent navigation safeguards could enable follow-on attacks or unauthorized content access.
- CVE-2026-11308MEDIUM 6.3
CVE-2026-11308 is a privilege escalation vulnerability in Google Chrome's extension system that allows an attacker to gain elevated permissions on a user's system. The attack requires social engineering—convincing a user to install a malicious browser extension—but once installed, the flaw in how Chrome enforces extension permissions allows the attacker to break out of the extension sandbox and perform actions at a higher privilege level than the extension should be allowed. This affects Windows, macOS, and Linux systems running Chrome versions prior to 149.0.7827.53.
- CVE-2026-11333MEDIUM 6.3
A file upload vulnerability exists in tittuvarghese CollegeManagementSystem that allows authenticated users to upload arbitrary files through the Student Data Upload endpoint. An attacker with login credentials can bypass upload restrictions by manipulating the Student-Data-CSV parameter, potentially introducing malicious files into the system. The vulnerability has been publicly disclosed and exploit code is available, though the project maintainers have not yet responded to the disclosure.
- CVE-2026-11335MEDIUM 6.3
A session fixation vulnerability has been discovered in tittuvarghese CollegeManagementSystem. An attacker can manipulate the UserAuthData parameter in the login form to hijack a user's session, potentially gaining unauthorized access to college management functions without requiring strong authentication. The vulnerability is remotely exploitable and does not require special access—any unauthenticated user can attempt the attack. Public exploit code is available, increasing the practical risk.
- CVE-2026-11336MEDIUM 6.3
A flaw in the College Management System allows authenticated users to bypass authorization controls and gain unauthorized access to sensitive administrative functions. An attacker with valid login credentials can manipulate a parameter called UserAuthData in the admin dashboard to perform actions they shouldn't be allowed to perform, potentially viewing, modifying, or deleting data. Because this vulnerability requires prior authentication and the exploit details are now public, it poses a meaningful security risk to organizations running this software.
- CVE-2026-11339MEDIUM 6.3
A command injection vulnerability exists in D-Link DWR-M920 routers up to firmware version 1.1.50. An authenticated attacker can inject arbitrary commands through the USSD Setup function, potentially gaining remote code execution on the device. The vulnerability requires valid login credentials but does not need user interaction to exploit. Public exploit code is now available.
- CVE-2026-11341MEDIUM 6.3
D-Link DWR-M920 routers up to firmware version 1.1.50 contain a command injection vulnerability in the IMEI setup form handler. An authenticated attacker can manipulate the IMEI_value parameter to execute arbitrary operating system commands on the affected device. The vulnerability requires valid login credentials but allows remote exploitation without user interaction once authenticated. Public exploit code has been released.
- CVE-2026-11406MEDIUM 6.3
GL.iNet MT3000 routers running firmware versions up to 4.4.5 contain a command injection flaw in the OpenVPN client import process. An authenticated user can craft a malicious OpenVPN configuration file that, when imported through the web interface, executes arbitrary system commands with the privileges of the router's web service. The vendor has released patched firmware that validates OpenVPN configuration files to block injection attempts.
- CVE-2026-11408MEDIUM 6.3
A remote code execution vulnerability exists in vertex-app versions up to 2026.02.12, where attackers with user-level access can inject arbitrary operating system commands through the Log Viewer endpoint. The flaw resides in how the application processes user-supplied query parameters without adequate sanitization, allowing an authenticated attacker to execute commands on the underlying server. Public exploit code is available, elevating practical risk despite the moderate CVSS score.
- CVE-2026-11412MEDIUM 6.3
Jinher OA C6 contains a SQL injection vulnerability in a web component that processes form identifiers. An attacker with login credentials can manipulate the queryID parameter in GetFormSyn.aspx to execute arbitrary database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is network-accessible and exploit code has been publicly released, increasing the risk of active exploitation.
- CVE-2026-11438MEDIUM 6.3
A security flaw in OneDev versions up to 15.0.5 allows authenticated users to manipulate project forking parameters in a way that bypasses authorization controls. An attacker with valid credentials can supply a crafted project ID in the forking mechanism to gain unauthorized access or modify projects they should not have permission to touch. This is a remote vulnerability requiring only standard user login—no special network access or user interaction needed beyond the attack itself.
- CVE-2026-11439MEDIUM 6.3
A vulnerability in OneDev up to version 15.0.5 allows authenticated users to manipulate parent project assignments in a way that bypasses authorization checks. An attacker with valid credentials can exploit the project.parentId parameter in the /projects/ endpoint to gain unauthorized access or make unauthorized changes to project hierarchies. This is a remote, network-accessible flaw that requires an existing user account to exploit.
- CVE-2026-11440MEDIUM 6.3
A vulnerability in OneDev versions up to 15.0.5 allows authenticated users to bypass authorization controls when modifying project default branch settings through the REST API. An attacker with login credentials can manipulate the `project.defaultBranch` parameter to gain unauthorized access or make changes they shouldn't be permitted to make. The vulnerability requires valid authentication to exploit but poses a moderate risk due to the potential for privilege escalation or unauthorized repository configuration changes.
- CVE-2026-11441MEDIUM 6.3
A flaw exists in theonedev onedev versions up to 15.0.5 that allows authenticated users to bypass authorization checks when accessing pull request issues. An attacker with valid credentials can manipulate how the system validates whether they have permission to view or modify specific issues, potentially gaining unauthorized access to sensitive project data. The vulnerability is straightforward to exploit once an attacker has credentials, and it requires only network access to the affected instance.
- CVE-2026-11447MEDIUM 6.3
A command injection vulnerability exists in GL.iNet's GL-MT3000 router firmware versions up to 4.4.5. The flaw is located in the MTK Backend component (iwinfo.so) and can be exploited by an authenticated remote attacker to inject arbitrary commands through the device parameter. This allows an attacker with valid credentials to execute unauthorized system commands. The vendor has released version 4.7 with global protections to intercept malicious injection attempts.
- CVE-2026-11449MEDIUM 6.3
GL.iNet has patched a command injection vulnerability affecting their GL-MT3000 router running firmware 4.4.5. An authenticated attacker could execute arbitrary commands through the LuCI JSON-RPC interface, potentially compromising the router and devices on its network. The vulnerability is addressed in firmware 4.8.1 and later, though newer versions (4.7.13+) mitigate it by excluding LuCI by default.
- CVE-2026-11453MEDIUM 6.3
Tiobon Employee Self-Service System versions up to 7.2 contain a SQL injection flaw in the blog search functionality accessible through the login endpoint. An authenticated attacker can manipulate search keywords to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials and has been publicly disclosed, though it is not currently tracked in the CISA Known Exploited Vulnerabilities catalog. The vendor has not acknowledged or addressed this issue despite early notification.
- CVE-2026-11461MEDIUM 6.3
NousResearch's hermes-agent contains a flaw that allows an authenticated user to bypass authorization checks by manipulating the 'Title' argument in the resume endpoint. An attacker with valid login credentials can access or modify information they shouldn't have permission to reach. The vulnerability affects versions up to 0.12.0, is remotely exploitable, and exploit details have been publicly disclosed.
- CVE-2026-11470MEDIUM 6.3
A path traversal vulnerability exists in the hsweb-framework file upload component that allows authenticated users to manipulate filenames and access files outside the intended upload directory. An attacker with valid credentials can exploit this flaw to read or write arbitrary files on the affected system by crafting malicious filename parameters. Public disclosure means this vulnerability has been shared in security communities, increasing the likelihood of active exploitation attempts.
- CVE-2026-11473MEDIUM 6.3
A SQL injection vulnerability exists in jflyfox jfinal_cms versions up to 5.1.0 that allows authenticated users to manipulate the orderBy parameter in the AdvicefeedbackController, potentially exposing or modifying database contents. The vulnerability requires valid login credentials but can be exploited over the network without user interaction once authenticated.
- CVE-2026-11475MEDIUM 6.3
A SQL injection vulnerability has been discovered in Kushan2k's student-management-system affecting the Certificate Verification Endpoint. An attacker with login credentials can manipulate the 'nic' parameter in the getStatus function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability is rated MEDIUM severity and exploits have been publicly disclosed, creating immediate risk for deployed instances.
- CVE-2026-11476MEDIUM 6.3
Kushan2k's student-management-system contains a flaw in its admin profile update endpoint that allows authenticated users to escalate their privileges by manipulating the 'isadmin' parameter. An attacker with legitimate credentials can modify this parameter to grant themselves administrative access without proper authorization checks. The vulnerability has already been disclosed publicly, and remote exploitation requires only network access and valid login credentials.
- CVE-2026-11480MEDIUM 6.3
A SQL injection vulnerability exists in BeikeShop, an e-commerce platform by Chengdu Everbrite Network Technology, affecting versions up to 1.6.0.22. An authenticated attacker can manipulate the 'settings.value' parameter in the Admin Design Builder endpoint to inject malicious SQL commands. The vulnerability requires login credentials but carries a network-based attack vector, allowing an attacker with admin or user-level access to read, modify, or delete database contents.
- CVE-2026-11495MEDIUM 6.3
CodeAstro Ingredients Stock Management System version 1.0 contains a SQL injection vulnerability in its stock addition functionality. An authenticated attacker can manipulate the ID parameter in the /Ingredients-Stock/add_stock.php file to execute arbitrary SQL queries. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid credentials to exploit but carries moderate severity due to its potential for data theft and integrity compromise.
- CVE-2026-11506MEDIUM 6.3
CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff deletion search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_for_deletion.php file to inject malicious SQL commands. This could allow unauthorized access to sensitive database information, modification of records, or disruption of the system. The vulnerability requires an authenticated login but poses a meaningful risk in environments where user accounts are shared or weak credential hygiene exists.
- CVE-2026-11507MEDIUM 6.3
A SQL injection vulnerability exists in CodeAstro Leave Management System version 1.0 that allows authenticated users to manipulate the leave_type parameter in the admin delete function, potentially extracting or modifying database information. The flaw requires valid login credentials but no additional user interaction, and public exploit code is available.
- CVE-2026-11508MEDIUM 6.3
CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff assignment search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_to_assign_pc.php file to inject malicious SQL commands. This allows remote exploitation without user interaction and poses a direct risk to database confidentiality, integrity, and availability. Public disclosure of this vulnerability means active exploitation is possible.
- CVE-2026-11509MEDIUM 6.3
CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff search functionality. An authenticated user can manipulate the Name parameter in the /admin/search_staff_for_updation.php file to inject arbitrary SQL commands, potentially reading or modifying sensitive employee and leave data. The vulnerability requires valid login credentials but poses a meaningful risk to organizations using this system, as it could enable unauthorized data access or manipulation by internal actors.
- CVE-2026-11510MEDIUM 6.3
CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its administrative interface. An authenticated attacker can manipulate the type_of_leave parameter when submitting leave requests through /admin/add_leave.php to inject malicious SQL commands. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid administrative credentials to exploit, but public exploit code is now available, increasing the practical risk.
- CVE-2026-11513MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the adminaccount.php file. An authenticated attacker can manipulate the Date parameter to inject arbitrary SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires valid login credentials but can be exploited over the network. Public exploits are available.
- CVE-2026-11514MEDIUM 6.3
itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in the patient admission form. An authenticated attacker can manipulate the admission time parameter in the /addpatient.php file to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials but can be exploited remotely with no additional user interaction.
- CVE-2026-11519MEDIUM 6.3
SourceCodester Inventory System version 1.0 contains a privilege escalation vulnerability in its user account creation mechanism. An authenticated attacker can manipulate the ROLE parameter during account creation to bypass authorization controls and gain elevated privileges. The vulnerability requires valid login credentials but can be exploited remotely without user interaction. Public exploits are available, increasing the likelihood of active exploitation.
- CVE-2026-11521MEDIUM 6.3
A security vulnerability exists in the Transaction Endpoint of the Mohammed-eid35 bank-management-system-springboot project that allows authenticated users to perform actions they shouldn't be authorized for. The flaw lies in the TransactionController component and enables an attacker with valid login credentials to manipulate transaction data beyond their permitted scope. Because this is a publicly disclosed vulnerability affecting a banking system component, prompt remediation is important even though exploitation requires existing user access.
- CVE-2026-11529MEDIUM 6.3
A SQL injection vulnerability exists in the mysql-mcp-server component (versions up to 0.2.2) that allows authenticated users to execute arbitrary SQL commands by manipulating URI parameters. An attacker with valid credentials can read, modify, or delete database records. The vulnerability has been publicly disclosed, increasing immediate risk. Upgrading to version 0.3.0 eliminates the issue.
- CVE-2026-11532MEDIUM 6.3
A security flaw has been discovered in imvks786's student management system that weakens access controls on student records. An authenticated user with basic access can manipulate requests to the Student Record Handler component (/add.php) to gain unauthorized permissions or modify data they shouldn't be able to touch. The vulnerability requires login credentials but can be exploited remotely. Public disclosure of exploitation techniques has already occurred, increasing near-term risk.
- CVE-2026-11558MEDIUM 6.3
CodeAstro Payroll System version 1.0 contains a SQL injection vulnerability in the /home_salary.php file. An authenticated attacker can manipulate the rate or salary_rate parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete sensitive payroll data. The vulnerability requires a valid user login but can be exploited over the network without user interaction once authenticated.
- CVE-2026-11559MEDIUM 6.3
A SQL injection vulnerability exists in CodeAstro Payroll System version 1.0 that allows authenticated users to manipulate database queries through the ID parameter in the /view_account.php file. An attacker with valid credentials can inject malicious SQL commands to access, modify, or delete sensitive payroll data. The vulnerability is network-accessible and does not require additional user interaction, though authentication is required. Public exploits are now available, increasing the risk of active exploitation.
- CVE-2026-11583MEDIUM 6.3
CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in the class creation administrative function. An authenticated attacker can manipulate the className input parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid login credentials but can be exploited over the network without additional user interaction.
- CVE-2026-11584MEDIUM 6.3
A SQL injection vulnerability exists in CodeAstro Student Attendance Management System version 1.0 that allows authenticated users to manipulate a parameter in the class editing interface and execute arbitrary database commands. An attacker with login credentials can inject malicious SQL through the ID argument to read, modify, or delete sensitive student and attendance data. The vulnerability is network-accessible and exploit code has been publicly disclosed, increasing the practical attack surface.
- CVE-2026-11585MEDIUM 6.3
CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its class management functionality. An authenticated attacker can manipulate the classId parameter in the createClassArms.php file to inject malicious SQL commands, potentially allowing unauthorized access to or modification of the database. The vulnerability requires user authentication but can be exploited remotely without user interaction.
- CVE-2026-11619MEDIUM 6.3
A flaw exists in Dolibarr ERP CRM versions up to 23.0.2 within the Legacy Filemanager component. An authenticated attacker can exploit improper authorization controls in a configuration file to gain unauthorized access to functionality they should not have. The vulnerability allows remote exploitation and does not require user interaction. Public exploit code is available, increasing practical attack risk. The issue is resolved by upgrading to version 23.0.3 or later.
- CVE-2026-12131MEDIUM 6.3
CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its Payroll Invoice Module. An authenticated attacker can manipulate the ID parameter in the invoice function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials to exploit but has low complexity and is accessible over the network. Public exploit code now exists, elevating the practical risk.
- CVE-2026-12188MEDIUM 6.3
Grit42 Grit versions up to 0.11.0 contain a SQL injection vulnerability in the GritEntityController component. An authenticated attacker can manipulate input to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive data. The vulnerability requires valid login credentials but can be exploited over the network without user interaction. Public exploits are available.
- CVE-2026-12206MEDIUM 6.3
Grit42's Grit framework versions up to 0.11.0 contain a SQL injection flaw in the DataTableEntity component. An authenticated attacker can exploit this remotely by manipulating input to the affected function, potentially allowing unauthorized access to, modification of, or deletion of database records. Public exploits exist for this vulnerability, elevating urgency for organizations using affected versions.
- CVE-2026-12210MEDIUM 6.3
CVE-2026-12210 is a server-side request forgery (SSRF) vulnerability in the python-utcp library version 1.1.0, affecting the utcp-gql and utcp-websocket components. An authenticated attacker can manipulate input to the affected function to make the vulnerable server initiate requests to internal or external systems on their behalf. This could expose sensitive data, bypass network segmentation, or interact with internal services. The vulnerability is publicly exploitable, and the vendor has not responded to early disclosure efforts.
- CVE-2026-12219MEDIUM 6.3
Yealink SIP-T46U phone systems running firmware version 108.86.0.118 contain a command injection vulnerability in their web-based diagnostic interface. An authenticated user can exploit this flaw by manipulating a time parameter to execute arbitrary system commands on the affected device. The vulnerability has been disclosed publicly, meaning attackers have knowledge of how to exploit it. Upgrading to firmware version 108.87.0.23 eliminates the risk.