2026 · Medium

Medium-severity vulnerabilities disclosed in 2026

Medium-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.

4010 published vulnerabilities · page 13 of 41

  • CVE-2026-12726MEDIUM 6.3

    AWX, an open-source automation platform, contains a vulnerability in how it handles GitHub webhook callbacks. When a job template is set up with GitHub credentials and receives a webhook notification about a pull request, the system doesn't properly verify that callback URLs are legitimate GitHub endpoints. An attacker who can craft a valid webhook message to the job template can trick the controller into sending sensitive GitHub credentials to an attacker-controlled server, exposing the stored Personal Access Token. The attack requires authenticated access to submit the forged webhook, but the impact—credential theft—is severe.

  • CVE-2026-12772MEDIUM 6.3

    A vulnerability in the BerriAI litellm proxy authentication system allows authenticated users to manipulate session handling logic, leading to session expiration. An attacker with valid credentials can trigger this flaw remotely through the PROXY_ADMIN database API Key Generator component. The vulnerability affects litellm versions up to and including 1.82.2. Public exploit code is available, increasing the practical risk of exploitation.

  • CVE-2026-12774MEDIUM 6.3

    BerriAI's litellm, an LLM proxy and management library, contains a server-side request forgery (SSRF) vulnerability in its MCP Server connection testing functionality. An authenticated attacker can manipulate the MCP Server Connection Testing feature to make the litellm server send arbitrary HTTP requests to internal or external systems on behalf of the attacker. This flaw affects litellm versions up to 1.82.2 and requires valid credentials to exploit, limiting immediate risk but creating a meaningful exposure for organizations running vulnerable instances accessible to untrusted users or in multi-tenant environments.

  • CVE-2026-12776MEDIUM 6.3

    Montodel House-Rental-Management contains a SQL injection vulnerability in its house listing functionality that allows authenticated attackers to manipulate database queries by injecting malicious SQL code through the ID parameter. An attacker with valid login credentials can exploit this remotely to read, modify, or delete sensitive rental property and customer data. Public exploit code is available, increasing the likelihood of active exploitation.

  • CVE-2026-12787MEDIUM 6.3

    A remote code execution vulnerability exists in zhilink's ADP Application Developer Platform version 1.0.0. An authenticated attacker can exploit a flaw in the testConnection endpoint by manipulating the jdbcUrl parameter to trigger unsafe deserialization, potentially allowing arbitrary code execution on the affected system. The vulnerability has already been disclosed publicly, and the vendor has not responded to disclosure attempts.

  • CVE-2026-12788MEDIUM 6.3

    A vulnerability in zhilink's ADP Application Developer Platform version 1.0.0 allows authenticated users to trigger XML External Entity (XXE) attacks through a barcode import function. An attacker with valid login credentials can craft malicious XML files to read sensitive files, modify data, or degrade system availability. The vulnerability has been publicly disclosed, and the vendor did not respond to early notification attempts.

  • CVE-2026-12796MEDIUM 6.3

    A flaw in BerriAI's litellm SSO authentication system allows authenticated users to trigger session expiration through manipulation of the OpenID redirect response handler. The vulnerability is network-accessible, requires valid credentials to exploit, and poses a moderate risk to applications relying on litellm's proxy authentication layer. Public exploit code exists, though no evidence of active weaponization in ransomware campaigns has been reported.

  • CVE-2026-12797MEDIUM 6.3

    A flaw in BerriAI's litellm library (versions up to 1.82.5) allows authenticated users to bypass keyword-based content filtering through manipulation of the prompt parameter in the Completions Interface. An attacker with valid credentials can craft requests that circumvent banned keyword restrictions, potentially exposing the system to restricted content or policy violations. Public exploit code exists for this issue.

  • CVE-2026-12798MEDIUM 6.3

    BerriAI's litellm library contains a server-side request forgery (SSRF) vulnerability in its MCP OpenAPI Spec Loader component. An authenticated attacker can manipulate the spec_path parameter to cause the server to make unintended network requests to internal or external systems. The vulnerability affects litellm versions up to 1.82.2 and requires valid authentication to exploit, limiting but not eliminating risk in many deployment scenarios.

  • CVE-2026-12805MEDIUM 6.3

    OFFIS DCMTK, a widely-used open-source DICOM toolkit for medical imaging, contains a buffer overflow vulnerability in its XML file parsing function. When the software processes a specially crafted XML file, an attacker can overwrite memory on the heap, potentially leading to information disclosure, data corruption, or application crash. The vulnerability requires user interaction—someone must open or process a malicious XML file—but no authentication is needed, and the attack can be triggered remotely by sending the file over the network.

  • CVE-2026-12807MEDIUM 6.3

    A command injection vulnerability exists in Edimax BR-6478AC V2 running firmware version 1.23. An authenticated attacker can send a specially crafted request to the router's WAN configuration endpoint to inject and execute arbitrary system commands. The vulnerability affects parameters used to configure PPP, PPTP, and L2TP username fields. Because the flaw requires an authenticated session and exploits have already been disclosed publicly, this poses a meaningful risk to organizations running this router model, particularly in environments where internal threat actors or compromised accounts could be leveraged.

  • CVE-2026-12808MEDIUM 6.3

    A command injection vulnerability has been discovered in Edimax BR-6478AC V2 running firmware version 1.23. An authenticated attacker can manipulate the 'interface' parameter in a POST request to the /goform/stainfo endpoint to execute arbitrary system commands. The vulnerability requires valid login credentials but poses a meaningful risk to organizations relying on this router model, particularly in environments where user accounts may be compromised or where trust boundaries are weak.

  • CVE-2026-12809MEDIUM 6.3

    A command injection vulnerability exists in Edimax BR-6478AC V2 running firmware 1.23. An authenticated attacker can manipulate the 'newpass' parameter in the wiz_5in1_redirect function to inject arbitrary commands, potentially compromising device integrity and data confidentiality. The vulnerability requires valid login credentials to exploit and is reachable over the network. Public exploit code is available.

  • CVE-2026-12810MEDIUM 6.3

    Edimax BR-6478AC V2 routers running firmware 1.23 contain a command injection vulnerability in their web management interface. An authenticated attacker can manipulate input to the mp endpoint and execute arbitrary system commands on the device. The vulnerability requires valid login credentials but no special privileges, and the exploit code is publicly available.

  • CVE-2026-12813MEDIUM 6.3

    Activepieces versions up to 0.83.0 contain a server-side request forgery (SSRF) vulnerability in the file URL handling component. An authenticated attacker can manipulate file URL processing to cause the server to make unintended requests to internal or external systems. The vulnerability requires valid user credentials to exploit but does not require user interaction. Public exploit code is available, increasing practical risk.

  • CVE-2026-12814MEDIUM 6.3

    Comfast CF-WR631AX V3 routers running firmware version 2.7.0.8 and earlier contain a command injection vulnerability in the ping configuration API endpoint. An authenticated attacker can manipulate the destination parameter to execute arbitrary operating system commands on the router. The vulnerability is remotely exploitable and proof-of-concept code has been published, though the vendor has not engaged on the disclosure or released patches.

  • CVE-2026-12815MEDIUM 6.3

    A vulnerability in Coolify 4.0.0 allows authenticated users to inject operating system commands through the Image Name Handler component. An attacker with valid login credentials could exploit this to execute arbitrary commands on the server hosting Coolify, potentially compromising the entire deployment platform and any applications it manages. The vendor was notified but has not yet released a public response, though version 4.1.2 includes input validation improvements that likely address this issue.

  • CVE-2026-12821MEDIUM 6.3

    FlowiseAI Flowise versions up to 3.1.2 contain a path traversal vulnerability in the S3 Document Loader component. An authenticated attacker can manipulate input to the S3.ts file to access files outside the intended directory structure, potentially exposing sensitive data or interacting with unauthorized resources on the S3 backend. The vulnerability requires valid user credentials but no special privileges to exploit.

  • CVE-2026-13356MEDIUM 6.3

    A flaw in Firefox for iOS allows a malicious webpage to create a deceptive visual state where the address bar shows one website while the page actually displays attacker-controlled content. This happens when a webpage interrupts a normal navigation by triggering a JavaScript dialog box at precisely the right moment. The browser's UI updates to reflect the legitimate destination, but the attacker's content continues to render behind or within that dialog, tricking users into believing they're on a safe site when they're not.

  • CVE-2026-13496MEDIUM 6.3

    CVE-2026-13496 is a SQL injection vulnerability in itsourcecode Hospital Management System version 1.0. An authenticated user can manipulate the medicineid parameter in the /ajaxmedicine.php file to inject malicious SQL commands, potentially allowing them to read, modify, or delete database records. The vulnerability requires login credentials but can be exploited remotely over the network. Public exploit code is available, increasing the practical risk.

  • CVE-2026-13497MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate database queries through the editid parameter in the appointment.php file. An attacker with valid credentials can exploit this flaw to read, modify, or delete sensitive hospital data, including patient records and appointment information. The vulnerability has been publicly disclosed, meaning exploitation guidance may be available to threat actors.

  • CVE-2026-13509MEDIUM 6.3

    RAGapp versions up to 0.1.5 contain a path traversal vulnerability in its file upload and removal functions. An authenticated attacker can manipulate file paths to read, write, or delete files outside the intended knowledge base directory, potentially compromising sensitive data or system integrity. The vulnerability requires login credentials but no special user privileges, and can be exploited over the network.

  • CVE-2026-13512MEDIUM 6.3

    Databend versions up to 1.2.881 contain a flaw in how it manages user sessions over HTTP that allows an authenticated attacker to bypass authorization checks. An attacker with valid credentials can manipulate session state to gain access to resources or actions they should not be permitted to perform. The vulnerability exists in the session state key generation logic and is known to be exploitable; proof-of-concept code is publicly available.

  • CVE-2026-13520MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in its appointment approval handler. An authenticated user can manipulate the 'editid' parameter in the /appointmentapproval.php file to inject SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid login credentials but poses genuine risk to hospitals relying on this system for critical appointment data. Public exploit code is available, raising the urgency of remediation.

  • CVE-2026-13525MEDIUM 6.3

    CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its leave update functionality. An authenticated user can manipulate the employee ID parameter to inject malicious SQL commands, potentially exposing, modifying, or deleting sensitive HR data. The vulnerability has been publicly disclosed and exploitation code is available.

  • CVE-2026-13530MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the 'editid' parameter in the /appointmentdetail.php file to inject malicious SQL commands. This vulnerability allows remote exploitation and could enable an attacker to read, modify, or delete sensitive appointment and patient data. Public exploits are available, increasing the risk of active exploitation.

  • CVE-2026-13531MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the /department.php file. An authenticated attacker can manipulate the editid parameter to execute arbitrary SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. Public exploit code is available, elevating the practical risk.

  • CVE-2026-13532MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in the departmentDoctor.php file that allows authenticated users to execute arbitrary SQL queries by manipulating the deptid parameter. An attacker with valid login credentials can remotely exploit this flaw to read, modify, or delete database records. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-13535MEDIUM 6.3

    CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its employee management interface. An authenticated user can manipulate the ID parameter in the file viewing function to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive HR data. The vulnerability requires valid login credentials but can be exploited remotely without special tools or user interaction.

  • CVE-2026-13538MEDIUM 6.3

    A command injection vulnerability exists in Wavlink WL-NU516U1-A M16U1_V240425 routers. An authenticated attacker can send specially crafted POST requests to the wireless configuration endpoint (/cgi-bin/wireless.cgi) with malicious input in SSID or authentication-related parameters. This allows execution of arbitrary system commands with the privileges of the web server process. The vulnerability requires valid credentials to exploit, but the attack surface is wide since SSID and password parameters are commonly modified during normal router administration.

  • CVE-2026-13540MEDIUM 6.3

    GitBucket versions up to 4.46.1 contain a server-side request forgery (SSRF) vulnerability in how they handle repository clone operations. An authenticated attacker can manipulate the URL argument passed to the repository creation function, causing the GitBucket server to make requests to unintended internal or external systems. The vulnerability requires valid login credentials to exploit but poses a meaningful risk to network confidentiality and integrity.

  • CVE-2026-13541MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0, specifically in the doctor password change functionality. An authenticated user can manipulate the newpassword parameter in /doctorchangepassword.php to inject malicious SQL commands. This allows an attacker to read, modify, or delete database contents without requiring elevated privileges. The vulnerability is remotely exploitable and public exploit code has already been released, increasing the risk of active exploitation.

  • CVE-2026-13542MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in its doctor profile functionality. An authenticated attacker can manipulate the doctorname parameter in /doctorprofile.php to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive healthcare data. The vulnerability requires valid login credentials but can be exploited without user interaction once authenticated. Public disclosure means defensive preparation should be treated as urgent.

  • CVE-2026-13544MEDIUM 6.3

    Feehi CMS versions up to 2.1.1 contain an access control flaw in its API user endpoint that allows authenticated attackers to perform unauthorized actions. An attacker with valid login credentials can bypass intended restrictions and access, modify, or delete user data that should be protected. The vulnerability is remotely exploitable and a proof-of-concept has already been published, increasing the practical risk of exploitation.

  • CVE-2026-13548MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate database queries through the editid parameter in the /doctortimings.php file. An attacker with valid login credentials can exploit this flaw to read, modify, or delete sensitive hospital data. The vulnerability is not yet tracked by CISA's Known Exploited Vulnerabilities catalog, but public exploit code is available, increasing the practical risk of opportunistic attacks.

  • CVE-2026-13560MEDIUM 6.3

    Edimax EW-7478APC wireless access points running firmware version 1.04 contain a command injection flaw in their web interface. An authenticated attacker can manipulate the 'submit-url' parameter sent to the device's configuration handler to execute arbitrary operating system commands. The vulnerability requires valid login credentials but can be exploited remotely over the network. Public details about this flaw are already available, increasing the risk of active exploitation.

  • CVE-2026-13561MEDIUM 6.3

    Edimax EW-7478APC version 1.04 contains a remote command injection vulnerability in its web interface. An authenticated attacker can manipulate the 'rootAPmac' parameter in the formiNICbasic POST request to execute arbitrary operating system commands on the device. The vulnerability has been publicly disclosed, and working exploits are available. The vendor was notified but has not responded or released a patch.

  • CVE-2026-13572MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to execute arbitrary SQL commands by manipulating the patientid parameter in the /insertbillingrecord.php file. An attacker with valid login credentials can exploit this remotely to read, modify, or delete database records. Public disclosure means defensive measures should be prioritized immediately.

  • CVE-2026-13578MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate the editid parameter in the patientdetail.php file, potentially compromising patient data confidentiality and integrity. The vulnerability requires valid login credentials but can be exploited remotely over the network. Public exploit code is already available, increasing the practical risk to deployed instances.

  • CVE-2026-13579MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the password change function to execute arbitrary SQL queries. This allows an attacker with valid login credentials to read, modify, or delete patient data stored in the hospital's database. The vulnerability is in the /patientchangepassword.php file and requires no user interaction beyond the attacker sending a crafted request.

  • CVE-2026-13581MEDIUM 6.3

    Edimax EW-7478APC wireless access point models running firmware version 1.04 contain a remote command injection flaw in the device's web interface. An authenticated attacker can send a specially crafted request to the POST handler at /goform/formStaDrvSetup, manipulating the rootAPmac parameter to execute arbitrary operating system commands on the device. This bypasses the device's normal administrative controls and allows an attacker to fully compromise the access point's security.

  • CVE-2026-13748MEDIUM 6.3

    Snowflake CLI versions before 3.19 contain a path traversal flaw that allows attackers to read arbitrary files from the local system. If an attacker can trick a user into processing malicious project or repository content, the CLI will read files outside the intended project directory and send their contents to Snowflake services. The attacker would then need to access the victim's Snowflake account—such as through query history or uploaded files—to retrieve the exfiltrated data. This requires user interaction and depends on the attacker having follow-on access to the Snowflake environment.

  • CVE-2026-14250MEDIUM 6.3

    The Themehunk Login Registration plugin for WordPress allows unauthenticated users to register new accounts with editor-level permissions when public registration is enabled. The vulnerability exists because the plugin accepts a user-supplied role parameter and validates it against all editable roles—which includes editor—without properly restricting what roles can be assigned during self-registration. An attacker can exploit this by creating an account with editor privileges, granting them significant control over site content and settings.

  • CVE-2026-14604MEDIUM 6.3

    Assimp, an open-source 3D model import/export library widely used in game engines, graphics applications, and CAD tools, contains a memory management flaw in its PLY (Polygon File Format) handler. When exporting 3D models to the PLY format, the library can inadvertently free the same memory region twice—a condition known as a double-free error. An authenticated attacker can trigger this flaw remotely by submitting a specially crafted PLY file, leading to application crash or potential code execution. The vulnerability affects Assimp versions up to and including 6.0.4.

  • CVE-2026-14619MEDIUM 6.3

    A SQL injection vulnerability has been discovered in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the 'editid' parameter in the /medicine.php file to inject malicious SQL commands. This allows an attacker who has valid login credentials to read, modify, or delete data in the underlying database. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14625MEDIUM 6.3

    NousResearch's hermes-agent, a tool for managing AI agent workflows, contains a vulnerability in how it handles shell execution commands. An authenticated attacker can bypass security controls that normally prevent dangerous operations, potentially gaining the ability to execute arbitrary commands on the affected system. The flaw exists in versions up to 0.15.2 and has already been disclosed publicly with working exploit code available, making it an active risk for organizations using vulnerable deployments.

  • CVE-2026-14638MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient.php file. An authenticated attacker can manipulate the 'editid' parameter to execute arbitrary SQL queries, potentially reading, modifying, or deleting patient data. The vulnerability requires valid login credentials but no additional user interaction, making it exploitable by insiders or through credential compromise. Public exploit code has been released.

  • CVE-2026-14639MEDIUM 6.3

    CodeAstro Ecommerce Website version 1.0 contains a SQL injection vulnerability in its customer account management functionality. An authenticated attacker can manipulate the 'c_name' parameter in the my_account.php?edit_account endpoint to inject malicious SQL commands, potentially compromising data confidentiality, integrity, and availability. Because the vulnerability requires prior authentication and has been publicly disclosed, it presents a moderate but actionable risk that organizations using this software should address promptly.

  • CVE-2026-14657MEDIUM 6.3

    A SQL injection vulnerability has been discovered in code-projects Assessment Management version 1.0. An authenticated attacker can inject malicious SQL code through the squestions[] parameter in the marking-scheme.php file, allowing them to read, modify, or delete database records. The vulnerability requires valid login credentials but does not require user interaction, making it a concern for organizations deploying this assessment platform.

  • CVE-2026-14658MEDIUM 6.3

    A SQL injection vulnerability exists in code-projects Assessment Management version 1.0 that allows authenticated users to manipulate the smarksrange[] parameter in the marking-scheme.php file to execute arbitrary SQL commands. An attacker with valid login credentials can exploit this remotely to read, modify, or delete database records without additional privileges. The vulnerability is already public and proof-of-concept code is available, raising the practical risk despite the medium CVSS score.

  • CVE-2026-14659MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient appointment functionality. An authenticated attacker can inject malicious SQL commands through the 'patiente' parameter in the /patientappointment.php file to read, modify, or delete database records. The vulnerability requires a valid user login but can be exploited remotely, and proof-of-concept details are publicly available.

  • CVE-2026-14689MEDIUM 6.3

    CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its apartment addition function. An authenticated attacker can manipulate the apartment number parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. Proof-of-concept code is publicly available, increasing the likelihood of active exploitation.

  • CVE-2026-14691MEDIUM 6.3

    SourceCodester Multi-Vendor Online Grocery Management System version 1.0 contains a code injection flaw in its settings update functionality. An authenticated attacker can manipulate the content parameter to inject malicious code, which the application will execute. The vulnerability requires login credentials but poses moderate risk due to the simplicity of exploitation and confirmed public disclosure.

  • CVE-2026-14692MEDIUM 6.3

    A SQL injection vulnerability exists in SourceCodester Multi-Vendor Online Grocery Management System versions 1.0 and 5.7.26. An authenticated attacker can inject malicious SQL commands through the POST parameters of the shop type save function, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials but no special privileges, and can be exploited over the network. Public exploit code is available.

  • CVE-2026-14694MEDIUM 6.3

    A SQL injection vulnerability exists in SourceCodester's Multi-Vendor Online Grocery Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the order cancellation function to inject malicious SQL commands. This allows an attacker with valid login credentials to read, modify, or delete database contents. The vulnerability was disclosed publicly, making attack techniques potentially available to a wider audience.

  • CVE-2026-14698MEDIUM 6.3

    SourceCodester's Syllabus-Aligned Learning Management and Examination System version 1.0 contains a file upload vulnerability that allows authenticated users to bypass upload restrictions. An attacker with login credentials can upload arbitrary files to the system, potentially leading to code execution, data theft, or system compromise. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14701MEDIUM 6.3

    A SQL injection vulnerability exists in the Internship Management System version 1.0, specifically in the password change function. An authenticated user can manipulate the 'Current' parameter to inject malicious SQL commands, potentially accessing or modifying sensitive data in the database. The vulnerability requires login credentials but is otherwise straightforward to exploit, and proof-of-concept code is already publicly available.

  • CVE-2026-14703MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate the editid parameter in the /patientorder.php file to execute arbitrary SQL queries. The vulnerability requires valid login credentials to exploit but does not require user interaction once authenticated. Public disclosure of this vulnerability means exploitation techniques are already available to potential attackers.

  • CVE-2026-14706MEDIUM 6.3

    A SQL injection vulnerability exists in code-projects Online Examination 1.0 affecting the quiz creation feature. An authenticated attacker can manipulate multiple input fields (name, total, right, wrong, time, tag, desc) in the /update.php?q=addquiz endpoint to inject malicious SQL commands. This allows unauthorized data access, modification, or deletion within the application's database. The vulnerability requires valid login credentials but can be exploited remotely with no user interaction.

  • CVE-2026-14716MEDIUM 6.3

    A flaw in nextlevelbuilder GoClaw's WebSocket RPC handler allows authenticated users to bypass authorization checks and gain unauthorized access to protected functionality. An attacker with valid credentials can exploit the MethodRouter.Handle function to perform actions they should not have permission to execute, including reading sensitive data or modifying system state. The vulnerability affects versions up to 3.13.0-beta.2 and has been publicly disclosed.

  • CVE-2026-14717MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient login function. An authenticated attacker can manipulate the loginid parameter in /patientlogin.php to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive patient data. The vulnerability requires valid credentials but is easy to exploit and poses a direct risk to healthcare information confidentiality and integrity.

  • CVE-2026-14725MEDIUM 6.3

    SourceCodester Online Boat Reservation System version 1.0 contains a vulnerability that allows authenticated users to trigger session expiration through unspecified manipulation. An attacker with valid credentials can remotely exploit this flaw to disrupt user sessions, affecting confidentiality, integrity, and availability of the application. Public exploit code is available, increasing the likelihood of active exploitation.

  • CVE-2026-14730MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0, specifically in the /patientprofile.php file. An authenticated attacker can manipulate the patientname parameter to execute arbitrary SQL commands against the underlying database. This allows an attacker who has legitimate system access to read, modify, or delete patient records and potentially other sensitive data. Public exploit code is available, increasing the practical risk.

  • CVE-2026-14731MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the /patientreport.php file. An authenticated attacker can manipulate the 'editid' parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete patient data. Public exploit code is available, increasing the practical risk of exploitation. The vulnerability requires valid login credentials but operates over the network without additional user interaction.

  • CVE-2026-14748MEDIUM 6.3

    AIAnytime's Awesome-MCP-Server contains a server-side request forgery (SSRF) vulnerability in its wiki-summary component. An authenticated attacker can manipulate the 'url' parameter to force the server to make unintended HTTP requests, potentially to internal systems or external targets. The vulnerability affects commits up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Because this project uses a rolling release model without versioned releases, patch status is unclear, and the vendor has not yet responded to early disclosure.

  • CVE-2026-14751MEDIUM 6.3

    A SQL injection vulnerability has been discovered in mjperpinosa stumasy, a rolling-release software project. An attacker with valid login credentials can inject malicious SQL commands through the search functionality by manipulating the field_name parameter. This allows unauthorized reading and modification of database records, or potentially disrupting database availability. Because the project uses continuous delivery and has not yet responded to disclosure, affected versions are not precisely documented.

  • CVE-2026-14766MEDIUM 6.3

    CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its search functionality. An authenticated attacker can exploit a flaw in the /apartment-visitor/search-result.php endpoint by manipulating the searchdata POST parameter to inject arbitrary SQL commands. This allows an attacker with valid login credentials to read, modify, or delete database records without authorization. Public exploit code exists for this vulnerability, increasing the practical risk.

  • CVE-2026-14767MEDIUM 6.3

    CodeAstro Ecommerce Website version 1.0 contains a SQL injection vulnerability in its customer confirmation page. An authenticated attacker can manipulate the invoice_no parameter to inject malicious SQL commands, potentially compromising database integrity and confidentiality. The vulnerability requires valid user credentials but no special interaction, and exploit code has already been released publicly.

  • CVE-2026-14773MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to inject malicious SQL commands through the patientid parameter in the /payment.php file. An attacker with valid login credentials can exploit this flaw to read, modify, or delete sensitive healthcare data. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14774MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the payment discharge workflow. An authenticated attacker can manipulate the patientid parameter in /paymentdischarge.php to execute unauthorized database queries, potentially reading, modifying, or deleting patient and financial records. The vulnerability requires valid login credentials but presents direct risk to patient data confidentiality and billing system integrity.

  • CVE-2026-14775MEDIUM 6.3

    A file upload vulnerability exists in SourceCodester's Online Examination & Learning Management System version 1.0. An authenticated attacker can bypass upload restrictions by manipulating the user_id parameter in the /process_lesson.php file, allowing them to upload malicious files to the system. The vulnerability requires valid login credentials but no special privileges. Exploit code is publicly available.

  • CVE-2026-14776MEDIUM 6.3

    SourceCodester's Online Examination & Learning Management System version 1.0 contains a file upload vulnerability that allows authenticated users to upload files with unrestricted extensions. An attacker with login credentials can bypass filename validation in the upload_files.php script to upload potentially dangerous file types, including executable code. Public exploit code is available, increasing the practical risk of active exploitation.

  • CVE-2026-14777MEDIUM 6.3

    A file upload vulnerability has been discovered in SourceCodester's Online Examination & Learning Management System version 1.0. An authenticated attacker can manipulate the /announcements.php file to upload files without proper restrictions. The vulnerability is accessible over the network and requires login credentials but no additional user interaction. Public exploit code is available, elevating the practical risk despite the CVSS score of 6.3.

  • CVE-2026-14784MEDIUM 6.3

    A vulnerability in vxcontrol PentAGI versions up to 2.1.0 allows authenticated users to bypass sandbox restrictions through improper Docker API handling. The flaw exists in the backend Docker client code and enables an attacker with valid credentials to potentially access or modify data outside intended security boundaries. Since the vulnerability requires prior authentication and does not yield remote code execution, the risk is constrained to insider threats or compromised account scenarios.

  • CVE-2026-14795MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Apartment Visitor Management System version 1.0. An authenticated attacker can manipulate the 'remark' parameter in the /apartment-visitor/action-visitor.php file to inject malicious SQL commands. This allows unauthorized access to, modification of, or deletion of database records. The vulnerability requires valid login credentials to exploit, and proof-of-concept code has been publicly disclosed.

  • CVE-2026-14796MEDIUM 6.3

    CodeAstro's Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its report generation feature. An authenticated attacker can manipulate the 'fromdate' parameter in the /apartment-visitor/report.php file to inject malicious SQL commands, potentially compromising the confidentiality, integrity, and availability of the application database. The exploit code is publicly available, increasing the practical risk to organizations using this software.

  • CVE-2026-14797MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Apartment Visitor Management System version 1.0. An authenticated user can manipulate the 'editid' parameter in the /apartment-visitor/edit-apartment.php file to inject malicious SQL commands. The vulnerability allows remote exploitation and has been publicly disclosed, increasing the risk of active exploitation.

  • CVE-2026-14798MEDIUM 6.3

    CVE-2026-14798 is a SQL injection vulnerability in CodeAstro Apartment Visitor Management System version 1.0. An authenticated attacker can inject malicious SQL code through the 'visname' parameter in the visitor entry form, potentially compromising the confidentiality, integrity, and availability of the underlying database. Public exploit code exists, elevating the practical risk despite the MEDIUM CVSS score.

  • CVE-2026-14799MEDIUM 6.3

    CodeAstro Ecommerce Website version 1.0 contains a SQL injection vulnerability in its customer account management functionality. An authenticated attacker can manipulate the delete_wishlist parameter in the /customer/my_account.php?my_wishlist endpoint to execute arbitrary SQL commands against the application's database. The flaw requires valid login credentials but no elevated privileges, and can be exploited over the network. Public exploit code exists, increasing the risk of active attacks.

  • CVE-2026-15033MEDIUM 6.3

    CVE-2026-15033 is a command injection vulnerability in the check-peer-dependencies npm package (versions up to 4.3.4) that allows an authenticated attacker to execute arbitrary operating system commands. The flaw exists in the peerDependencies component where user-controlled input is passed unsanitized to a shell execution function, enabling remote code execution for any user with access to the affected package.

  • CVE-2026-15044MEDIUM 6.3

    CVE-2026-15044 is a configuration flaw in the TrustyAI Service Operator that can leave AI guardrails and orchestration services (gorch and NemoGuardrails) exposed within Kubernetes clusters. When a specific security setting is disabled—the default or an oversight during deployment—these services skip authentication checks. Any workload running in the cluster can then communicate directly with these AI services, potentially reading sensitive information or making unauthorized modifications to model behavior. The vulnerability requires cluster-level access, so external attackers cannot exploit it remotely, but insider threats and compromised applications represent realistic attack vectors.

  • CVE-2026-15063MEDIUM 6.3

    CVE-2026-15063 is a network access control flaw in the trustyai-service-operator's gorch service template. Even when authentication is enabled, the service leaves its orchestrator and detector metrics ports exposed without protection, allowing any pod with network access to the cluster to read sensitive metrics directly. This bypasses the Kubernetes RBAC proxy and authentication controls that should guard these endpoints.

  • CVE-2026-15105MEDIUM 6.3

    A memory corruption vulnerability exists in snap7, an open-source library for communicating with Siemens S7 PLCs, affecting versions up to 1.4.3. When processing certain ReadVar requests, the TS7Worker::PerformFunctionRead handler writes data beyond the bounds of an allocated buffer. An attacker with access to the local network can trigger this flaw to corrupt memory, potentially causing crashes or enabling code execution. The vulnerability is publicly exploitable; proof-of-concept code has been released and the vendor has not yet issued a patch or timeline for remediation.

  • CVE-2026-15138MEDIUM 6.3

    A path traversal vulnerability exists in tumf's mcp-text-editor software (versions up to 1.0.2) that allows an attacker to access files outside the intended directory through manipulation of file path parameters. The vulnerability requires user interaction to exploit but can be triggered remotely. Public disclosure has already occurred, increasing the likelihood of active exploitation attempts.

  • CVE-2026-15186MEDIUM 6.3

    A vulnerability exists in macrozheng mall versions up to 1.0.3 that allows authenticated attackers to manipulate order identifiers when creating return applications. By tampering with the orderId parameter in the /returnApply/create endpoint, an attacker can gain unauthorized access to or modify orders belonging to other users. The vulnerability requires an active user session but does not require elevated privileges, and it can be exploited entirely over the network. A public exploit is available.

  • CVE-2026-15188MEDIUM 6.3

    A vulnerability in the django-job-portal application allows authenticated users to bypass access controls by manipulating the 'role' parameter in the Employee Dashboard endpoint. This could enable a logged-in employee to view, modify, or delete information they shouldn't have access to, such as salary data, performance reviews, or other employees' records. The flaw affects the EditEmployeeProfileAPIView function and requires an attacker to already have valid login credentials.

  • CVE-2026-15189MEDIUM 6.3

    A server-side request forgery (SSRF) vulnerability exists in aerostack-mcp, specifically in the WhatsApp media upload component. An authenticated attacker can manipulate the media_url parameter to make the server perform unintended HTTP requests to internal or external systems. This could allow access to sensitive internal resources, data exfiltration, or further lateral movement within a network. The vulnerability affects all versions up to commit 6315dfde7df0a15aaf743f88d91347115e09ba23. The project uses a rolling release model, meaning patches are deployed continuously rather than in numbered versions.

  • CVE-2026-15191MEDIUM 6.3

    Mettle SendPortal, a campaign management platform, contains an authorization bypass vulnerability in its Campaign Creation endpoint that allows authenticated users to perform unauthorized actions. The flaw exists in how the application validates user permissions when creating campaigns, potentially enabling an attacker with basic user credentials to manipulate campaign data or access restricted functionality. The vulnerability affects SendPortal versions up to 3.0.1 and can be exploited remotely without user interaction. A proof-of-concept has been publicly disclosed.

  • CVE-2026-15195MEDIUM 6.3

    A prototype pollution vulnerability has been identified in the apidevtools json-schema-ref-parser library (versions up to 15.3.5). The flaw allows authenticated attackers to improperly modify object prototype attributes through the Refs.set and Pointer.set functions. This can be exploited remotely and may lead to unauthorized data modification or application behavior changes. Upgrading to version 15.3.6 resolves the issue.

  • CVE-2026-15317MEDIUM 6.3

    Sipeed PicoClaw versions up to 0.2.9 contain a server-side request forgery (SSRF) vulnerability in its web fetch functionality. An unauthenticated remote attacker can manipulate the WebFetchTool component to make the server issue requests to unintended destinations—potentially accessing internal resources, cloud metadata services, or other backend systems that should be isolated. The vulnerability requires user interaction (clicking a link or visiting a crafted page), and public exploit code is already available.

  • CVE-2026-15318MEDIUM 6.3

    Sipeed PicoClaw, an embedded development board tool, contains a flaw in how it validates user permissions when processing MQTT connections. By manipulating the client ID parameter sent to the MQTT handler, an authenticated attacker can bypass authorization checks and gain unauthorized access to resources they shouldn't reach. The vulnerability affects versions up to 0.2.9 and can be triggered remotely without user interaction once an attacker has valid credentials.

  • CVE-2026-15332MEDIUM 6.3

    A flaw in zhayujie CowAgent (versions up to 2.1.0) allows authenticated users to perform unauthorized actions through the Message Endpoint. The vulnerability exists in the channel/channel.py component and lacks proper authorization checks, meaning someone with basic login credentials could potentially access or modify data they shouldn't be able to. An exploit has already been published publicly, making active exploitation more likely.

  • CVE-2026-15373MEDIUM 6.3

    Eleveo Call Recording Software version 9.7.0 contains an authorization flaw that allows authenticated users to escalate privileges by manipulating the 'role' parameter sent to the /callrec/userAddAction.do endpoint. An attacker with legitimate access can modify this parameter to grant themselves higher privilege levels or create accounts with elevated permissions. The vulnerability requires an existing user account but can be exploited remotely without user interaction. Public exploit code is available.

  • CVE-2026-15374MEDIUM 6.3

    Eleveo Call Recording Software version 9.7.0 contains an authorization flaw in its Group Interface component. An authenticated attacker can manipulate requests to the /callrec/roleAddAction.do endpoint to bypass access controls, potentially gaining unauthorized actions within the system. The vulnerability requires valid user credentials but can be exploited remotely without user interaction. Public exploit code is available.

  • CVE-2026-15376MEDIUM 6.3

    Eleveo Call Recording Software version 9.7.0 contains an authorization bypass vulnerability in its statistics reporting functionality. A remote attacker who has already obtained valid credentials can exploit this weakness to access or modify data they shouldn't be able to reach. The vulnerability is already public and functional exploits exist, though the vendor has not engaged on remediation efforts.

  • CVE-2026-20220MEDIUM 6.3

    Cisco Crosswork Network Controller's web management interface contains a flaw in how it validates input to its configuration template engine. An authenticated user with template write permissions can send specially crafted requests to execute arbitrary commands on the underlying operating system, but only within directories where the template user account has write access. This is a post-authentication attack requiring valid credentials and specific permission levels.

  • CVE-2026-21404MEDIUM 6.3

    NAVTOR NavBox versions up to 4.16.1.20 contain hard-coded credentials embedded in its SOAP (Windows Communication Foundation) implementation. When SOAP functionality is enabled, a local user with basic system access can extract these credentials, authenticate to the SOAP interface, and gain unauthorized access to privileged methods that allow arbitrary file write and overwrite operations on the system. This vulnerability requires local access to trigger but bypasses intended security workflows entirely.

  • CVE-2026-21768MEDIUM 6.3

    CVE-2026-21768 is a medium-severity vulnerability in the compose-rich-editor library used by HCL Verse for Android. The library does not properly validate HTML input during email composition, potentially allowing malicious content to execute. Exploitation requires local access and user interaction—an attacker must trick a user into opening a crafted email or triggering composition of malicious content on the device itself.

  • CVE-2026-25599MEDIUM 6.3

    This vulnerability affects Orca heat pump devices and their control portal. An attacker can intercept unencrypted communications between older Orca heat pumps and the control server, impersonate a legitimate device, and inject malicious code into the web portal. This injected code can steal user session cookies, compromise accounts, expose sensitive information, and grant attackers unauthorized access to the portal. The core issues are the lack of authentication, unencrypted HTTP connections, and missing input validation.

  • CVE-2026-35716MEDIUM 6.3

    A stack-based buffer overflow vulnerability exists in VIVOTEK FD8136 IP cameras that allows an authenticated attacker to run arbitrary code with root privileges. The flaw is in the motion privacy configuration endpoint, which fails to validate the size of user input before copying it into a fixed-size buffer on the stack. Because the camera firmware lacks stack protection mechanisms, an attacker can overwrite return addresses and hijack program execution. An authenticated attacker on the network can exploit this remotely by sending a specially crafted POST request.