By year

Vulnerabilities disclosed in 2026

CVEs published in 2026 with SEC.co analysis.

8541 published vulnerabilities · page 54 of 86

  • CVE-2026-11341MEDIUM 6.3

    D-Link DWR-M920 routers up to firmware version 1.1.50 contain a command injection vulnerability in the IMEI setup form handler. An authenticated attacker can manipulate the IMEI_value parameter to execute arbitrary operating system commands on the affected device. The vulnerability requires valid login credentials but allows remote exploitation without user interaction once authenticated. Public exploit code has been released.

  • CVE-2026-11406MEDIUM 6.3

    GL.iNet MT3000 routers running firmware versions up to 4.4.5 contain a command injection flaw in the OpenVPN client import process. An authenticated user can craft a malicious OpenVPN configuration file that, when imported through the web interface, executes arbitrary system commands with the privileges of the router's web service. The vendor has released patched firmware that validates OpenVPN configuration files to block injection attempts.

  • CVE-2026-11408MEDIUM 6.3

    A remote code execution vulnerability exists in vertex-app versions up to 2026.02.12, where attackers with user-level access can inject arbitrary operating system commands through the Log Viewer endpoint. The flaw resides in how the application processes user-supplied query parameters without adequate sanitization, allowing an authenticated attacker to execute commands on the underlying server. Public exploit code is available, elevating practical risk despite the moderate CVSS score.

  • CVE-2026-11412MEDIUM 6.3

    Jinher OA C6 contains a SQL injection vulnerability in a web component that processes form identifiers. An attacker with login credentials can manipulate the queryID parameter in GetFormSyn.aspx to execute arbitrary database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is network-accessible and exploit code has been publicly released, increasing the risk of active exploitation.

  • CVE-2026-11438MEDIUM 6.3

    A security flaw in OneDev versions up to 15.0.5 allows authenticated users to manipulate project forking parameters in a way that bypasses authorization controls. An attacker with valid credentials can supply a crafted project ID in the forking mechanism to gain unauthorized access or modify projects they should not have permission to touch. This is a remote vulnerability requiring only standard user login—no special network access or user interaction needed beyond the attack itself.

  • CVE-2026-11439MEDIUM 6.3

    A vulnerability in OneDev up to version 15.0.5 allows authenticated users to manipulate parent project assignments in a way that bypasses authorization checks. An attacker with valid credentials can exploit the project.parentId parameter in the /projects/ endpoint to gain unauthorized access or make unauthorized changes to project hierarchies. This is a remote, network-accessible flaw that requires an existing user account to exploit.

  • CVE-2026-11440MEDIUM 6.3

    A vulnerability in OneDev versions up to 15.0.5 allows authenticated users to bypass authorization controls when modifying project default branch settings through the REST API. An attacker with login credentials can manipulate the `project.defaultBranch` parameter to gain unauthorized access or make changes they shouldn't be permitted to make. The vulnerability requires valid authentication to exploit but poses a moderate risk due to the potential for privilege escalation or unauthorized repository configuration changes.

  • CVE-2026-11441MEDIUM 6.3

    A flaw exists in theonedev onedev versions up to 15.0.5 that allows authenticated users to bypass authorization checks when accessing pull request issues. An attacker with valid credentials can manipulate how the system validates whether they have permission to view or modify specific issues, potentially gaining unauthorized access to sensitive project data. The vulnerability is straightforward to exploit once an attacker has credentials, and it requires only network access to the affected instance.

  • CVE-2026-11447MEDIUM 6.3

    A command injection vulnerability exists in GL.iNet's GL-MT3000 router firmware versions up to 4.4.5. The flaw is located in the MTK Backend component (iwinfo.so) and can be exploited by an authenticated remote attacker to inject arbitrary commands through the device parameter. This allows an attacker with valid credentials to execute unauthorized system commands. The vendor has released version 4.7 with global protections to intercept malicious injection attempts.

  • CVE-2026-11449MEDIUM 6.3

    GL.iNet has patched a command injection vulnerability affecting their GL-MT3000 router running firmware 4.4.5. An authenticated attacker could execute arbitrary commands through the LuCI JSON-RPC interface, potentially compromising the router and devices on its network. The vulnerability is addressed in firmware 4.8.1 and later, though newer versions (4.7.13+) mitigate it by excluding LuCI by default.

  • CVE-2026-11453MEDIUM 6.3

    Tiobon Employee Self-Service System versions up to 7.2 contain a SQL injection flaw in the blog search functionality accessible through the login endpoint. An authenticated attacker can manipulate search keywords to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials and has been publicly disclosed, though it is not currently tracked in the CISA Known Exploited Vulnerabilities catalog. The vendor has not acknowledged or addressed this issue despite early notification.

  • CVE-2026-11461MEDIUM 6.3

    NousResearch's hermes-agent contains a flaw that allows an authenticated user to bypass authorization checks by manipulating the 'Title' argument in the resume endpoint. An attacker with valid login credentials can access or modify information they shouldn't have permission to reach. The vulnerability affects versions up to 0.12.0, is remotely exploitable, and exploit details have been publicly disclosed.

  • CVE-2026-11470MEDIUM 6.3

    A path traversal vulnerability exists in the hsweb-framework file upload component that allows authenticated users to manipulate filenames and access files outside the intended upload directory. An attacker with valid credentials can exploit this flaw to read or write arbitrary files on the affected system by crafting malicious filename parameters. Public disclosure means this vulnerability has been shared in security communities, increasing the likelihood of active exploitation attempts.

  • CVE-2026-11473MEDIUM 6.3

    A SQL injection vulnerability exists in jflyfox jfinal_cms versions up to 5.1.0 that allows authenticated users to manipulate the orderBy parameter in the AdvicefeedbackController, potentially exposing or modifying database contents. The vulnerability requires valid login credentials but can be exploited over the network without user interaction once authenticated.

  • CVE-2026-11475MEDIUM 6.3

    A SQL injection vulnerability has been discovered in Kushan2k's student-management-system affecting the Certificate Verification Endpoint. An attacker with login credentials can manipulate the 'nic' parameter in the getStatus function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability is rated MEDIUM severity and exploits have been publicly disclosed, creating immediate risk for deployed instances.

  • CVE-2026-11476MEDIUM 6.3

    Kushan2k's student-management-system contains a flaw in its admin profile update endpoint that allows authenticated users to escalate their privileges by manipulating the 'isadmin' parameter. An attacker with legitimate credentials can modify this parameter to grant themselves administrative access without proper authorization checks. The vulnerability has already been disclosed publicly, and remote exploitation requires only network access and valid login credentials.

  • CVE-2026-11480MEDIUM 6.3

    A SQL injection vulnerability exists in BeikeShop, an e-commerce platform by Chengdu Everbrite Network Technology, affecting versions up to 1.6.0.22. An authenticated attacker can manipulate the 'settings.value' parameter in the Admin Design Builder endpoint to inject malicious SQL commands. The vulnerability requires login credentials but carries a network-based attack vector, allowing an attacker with admin or user-level access to read, modify, or delete database contents.

  • CVE-2026-11495MEDIUM 6.3

    CodeAstro Ingredients Stock Management System version 1.0 contains a SQL injection vulnerability in its stock addition functionality. An authenticated attacker can manipulate the ID parameter in the /Ingredients-Stock/add_stock.php file to execute arbitrary SQL queries. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid credentials to exploit but carries moderate severity due to its potential for data theft and integrity compromise.

  • CVE-2026-11506MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff deletion search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_for_deletion.php file to inject malicious SQL commands. This could allow unauthorized access to sensitive database information, modification of records, or disruption of the system. The vulnerability requires an authenticated login but poses a meaningful risk in environments where user accounts are shared or weak credential hygiene exists.

  • CVE-2026-11507MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Leave Management System version 1.0 that allows authenticated users to manipulate the leave_type parameter in the admin delete function, potentially extracting or modifying database information. The flaw requires valid login credentials but no additional user interaction, and public exploit code is available.

  • CVE-2026-11508MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff assignment search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_to_assign_pc.php file to inject malicious SQL commands. This allows remote exploitation without user interaction and poses a direct risk to database confidentiality, integrity, and availability. Public disclosure of this vulnerability means active exploitation is possible.

  • CVE-2026-11509MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff search functionality. An authenticated user can manipulate the Name parameter in the /admin/search_staff_for_updation.php file to inject arbitrary SQL commands, potentially reading or modifying sensitive employee and leave data. The vulnerability requires valid login credentials but poses a meaningful risk to organizations using this system, as it could enable unauthorized data access or manipulation by internal actors.

  • CVE-2026-11510MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its administrative interface. An authenticated attacker can manipulate the type_of_leave parameter when submitting leave requests through /admin/add_leave.php to inject malicious SQL commands. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid administrative credentials to exploit, but public exploit code is now available, increasing the practical risk.

  • CVE-2026-11513MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the adminaccount.php file. An authenticated attacker can manipulate the Date parameter to inject arbitrary SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires valid login credentials but can be exploited over the network. Public exploits are available.

  • CVE-2026-11514MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in the patient admission form. An authenticated attacker can manipulate the admission time parameter in the /addpatient.php file to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials but can be exploited remotely with no additional user interaction.

  • CVE-2026-11519MEDIUM 6.3

    SourceCodester Inventory System version 1.0 contains a privilege escalation vulnerability in its user account creation mechanism. An authenticated attacker can manipulate the ROLE parameter during account creation to bypass authorization controls and gain elevated privileges. The vulnerability requires valid login credentials but can be exploited remotely without user interaction. Public exploits are available, increasing the likelihood of active exploitation.

  • CVE-2026-11521MEDIUM 6.3

    A security vulnerability exists in the Transaction Endpoint of the Mohammed-eid35 bank-management-system-springboot project that allows authenticated users to perform actions they shouldn't be authorized for. The flaw lies in the TransactionController component and enables an attacker with valid login credentials to manipulate transaction data beyond their permitted scope. Because this is a publicly disclosed vulnerability affecting a banking system component, prompt remediation is important even though exploitation requires existing user access.

  • CVE-2026-11529MEDIUM 6.3

    A SQL injection vulnerability exists in the mysql-mcp-server component (versions up to 0.2.2) that allows authenticated users to execute arbitrary SQL commands by manipulating URI parameters. An attacker with valid credentials can read, modify, or delete database records. The vulnerability has been publicly disclosed, increasing immediate risk. Upgrading to version 0.3.0 eliminates the issue.

  • CVE-2026-11532MEDIUM 6.3

    A security flaw has been discovered in imvks786's student management system that weakens access controls on student records. An authenticated user with basic access can manipulate requests to the Student Record Handler component (/add.php) to gain unauthorized permissions or modify data they shouldn't be able to touch. The vulnerability requires login credentials but can be exploited remotely. Public disclosure of exploitation techniques has already occurred, increasing near-term risk.

  • CVE-2026-11558MEDIUM 6.3

    CodeAstro Payroll System version 1.0 contains a SQL injection vulnerability in the /home_salary.php file. An authenticated attacker can manipulate the rate or salary_rate parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete sensitive payroll data. The vulnerability requires a valid user login but can be exploited over the network without user interaction once authenticated.

  • CVE-2026-11559MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Payroll System version 1.0 that allows authenticated users to manipulate database queries through the ID parameter in the /view_account.php file. An attacker with valid credentials can inject malicious SQL commands to access, modify, or delete sensitive payroll data. The vulnerability is network-accessible and does not require additional user interaction, though authentication is required. Public exploits are now available, increasing the risk of active exploitation.

  • CVE-2026-11583MEDIUM 6.3

    CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in the class creation administrative function. An authenticated attacker can manipulate the className input parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid login credentials but can be exploited over the network without additional user interaction.

  • CVE-2026-11584MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Student Attendance Management System version 1.0 that allows authenticated users to manipulate a parameter in the class editing interface and execute arbitrary database commands. An attacker with login credentials can inject malicious SQL through the ID argument to read, modify, or delete sensitive student and attendance data. The vulnerability is network-accessible and exploit code has been publicly disclosed, increasing the practical attack surface.

  • CVE-2026-11585MEDIUM 6.3

    CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its class management functionality. An authenticated attacker can manipulate the classId parameter in the createClassArms.php file to inject malicious SQL commands, potentially allowing unauthorized access to or modification of the database. The vulnerability requires user authentication but can be exploited remotely without user interaction.

  • CVE-2026-11619MEDIUM 6.3

    A flaw exists in Dolibarr ERP CRM versions up to 23.0.2 within the Legacy Filemanager component. An authenticated attacker can exploit improper authorization controls in a configuration file to gain unauthorized access to functionality they should not have. The vulnerability allows remote exploitation and does not require user interaction. Public exploit code is available, increasing practical attack risk. The issue is resolved by upgrading to version 23.0.3 or later.

  • CVE-2026-12131MEDIUM 6.3

    CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its Payroll Invoice Module. An authenticated attacker can manipulate the ID parameter in the invoice function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials to exploit but has low complexity and is accessible over the network. Public exploit code now exists, elevating the practical risk.

  • CVE-2026-12188MEDIUM 6.3

    Grit42 Grit versions up to 0.11.0 contain a SQL injection vulnerability in the GritEntityController component. An authenticated attacker can manipulate input to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive data. The vulnerability requires valid login credentials but can be exploited over the network without user interaction. Public exploits are available.

  • CVE-2026-12206MEDIUM 6.3

    Grit42's Grit framework versions up to 0.11.0 contain a SQL injection flaw in the DataTableEntity component. An authenticated attacker can exploit this remotely by manipulating input to the affected function, potentially allowing unauthorized access to, modification of, or deletion of database records. Public exploits exist for this vulnerability, elevating urgency for organizations using affected versions.

  • CVE-2026-12210MEDIUM 6.3

    CVE-2026-12210 is a server-side request forgery (SSRF) vulnerability in the python-utcp library version 1.1.0, affecting the utcp-gql and utcp-websocket components. An authenticated attacker can manipulate input to the affected function to make the vulnerable server initiate requests to internal or external systems on their behalf. This could expose sensitive data, bypass network segmentation, or interact with internal services. The vulnerability is publicly exploitable, and the vendor has not responded to early disclosure efforts.

  • CVE-2026-12219MEDIUM 6.3

    Yealink SIP-T46U phone systems running firmware version 108.86.0.118 contain a command injection vulnerability in their web-based diagnostic interface. An authenticated user can exploit this flaw by manipulating a time parameter to execute arbitrary system commands on the affected device. The vulnerability has been disclosed publicly, meaning attackers have knowledge of how to exploit it. Upgrading to firmware version 108.87.0.23 eliminates the risk.

  • CVE-2026-12726MEDIUM 6.3

    AWX, an open-source automation platform, contains a vulnerability in how it handles GitHub webhook callbacks. When a job template is set up with GitHub credentials and receives a webhook notification about a pull request, the system doesn't properly verify that callback URLs are legitimate GitHub endpoints. An attacker who can craft a valid webhook message to the job template can trick the controller into sending sensitive GitHub credentials to an attacker-controlled server, exposing the stored Personal Access Token. The attack requires authenticated access to submit the forged webhook, but the impact—credential theft—is severe.

  • CVE-2026-12772MEDIUM 6.3

    A vulnerability in the BerriAI litellm proxy authentication system allows authenticated users to manipulate session handling logic, leading to session expiration. An attacker with valid credentials can trigger this flaw remotely through the PROXY_ADMIN database API Key Generator component. The vulnerability affects litellm versions up to and including 1.82.2. Public exploit code is available, increasing the practical risk of exploitation.

  • CVE-2026-12774MEDIUM 6.3

    BerriAI's litellm, an LLM proxy and management library, contains a server-side request forgery (SSRF) vulnerability in its MCP Server connection testing functionality. An authenticated attacker can manipulate the MCP Server Connection Testing feature to make the litellm server send arbitrary HTTP requests to internal or external systems on behalf of the attacker. This flaw affects litellm versions up to 1.82.2 and requires valid credentials to exploit, limiting immediate risk but creating a meaningful exposure for organizations running vulnerable instances accessible to untrusted users or in multi-tenant environments.

  • CVE-2026-12776MEDIUM 6.3

    Montodel House-Rental-Management contains a SQL injection vulnerability in its house listing functionality that allows authenticated attackers to manipulate database queries by injecting malicious SQL code through the ID parameter. An attacker with valid login credentials can exploit this remotely to read, modify, or delete sensitive rental property and customer data. Public exploit code is available, increasing the likelihood of active exploitation.

  • CVE-2026-12787MEDIUM 6.3

    A remote code execution vulnerability exists in zhilink's ADP Application Developer Platform version 1.0.0. An authenticated attacker can exploit a flaw in the testConnection endpoint by manipulating the jdbcUrl parameter to trigger unsafe deserialization, potentially allowing arbitrary code execution on the affected system. The vulnerability has already been disclosed publicly, and the vendor has not responded to disclosure attempts.

  • CVE-2026-12788MEDIUM 6.3

    A vulnerability in zhilink's ADP Application Developer Platform version 1.0.0 allows authenticated users to trigger XML External Entity (XXE) attacks through a barcode import function. An attacker with valid login credentials can craft malicious XML files to read sensitive files, modify data, or degrade system availability. The vulnerability has been publicly disclosed, and the vendor did not respond to early notification attempts.

  • CVE-2026-12796MEDIUM 6.3

    A flaw in BerriAI's litellm SSO authentication system allows authenticated users to trigger session expiration through manipulation of the OpenID redirect response handler. The vulnerability is network-accessible, requires valid credentials to exploit, and poses a moderate risk to applications relying on litellm's proxy authentication layer. Public exploit code exists, though no evidence of active weaponization in ransomware campaigns has been reported.

  • CVE-2026-12797MEDIUM 6.3

    A flaw in BerriAI's litellm library (versions up to 1.82.5) allows authenticated users to bypass keyword-based content filtering through manipulation of the prompt parameter in the Completions Interface. An attacker with valid credentials can craft requests that circumvent banned keyword restrictions, potentially exposing the system to restricted content or policy violations. Public exploit code exists for this issue.

  • CVE-2026-12798MEDIUM 6.3

    BerriAI's litellm library contains a server-side request forgery (SSRF) vulnerability in its MCP OpenAPI Spec Loader component. An authenticated attacker can manipulate the spec_path parameter to cause the server to make unintended network requests to internal or external systems. The vulnerability affects litellm versions up to 1.82.2 and requires valid authentication to exploit, limiting but not eliminating risk in many deployment scenarios.

  • CVE-2026-12805MEDIUM 6.3

    OFFIS DCMTK, a widely-used open-source DICOM toolkit for medical imaging, contains a buffer overflow vulnerability in its XML file parsing function. When the software processes a specially crafted XML file, an attacker can overwrite memory on the heap, potentially leading to information disclosure, data corruption, or application crash. The vulnerability requires user interaction—someone must open or process a malicious XML file—but no authentication is needed, and the attack can be triggered remotely by sending the file over the network.

  • CVE-2026-12807MEDIUM 6.3

    A command injection vulnerability exists in Edimax BR-6478AC V2 running firmware version 1.23. An authenticated attacker can send a specially crafted request to the router's WAN configuration endpoint to inject and execute arbitrary system commands. The vulnerability affects parameters used to configure PPP, PPTP, and L2TP username fields. Because the flaw requires an authenticated session and exploits have already been disclosed publicly, this poses a meaningful risk to organizations running this router model, particularly in environments where internal threat actors or compromised accounts could be leveraged.

  • CVE-2026-12808MEDIUM 6.3

    A command injection vulnerability has been discovered in Edimax BR-6478AC V2 running firmware version 1.23. An authenticated attacker can manipulate the 'interface' parameter in a POST request to the /goform/stainfo endpoint to execute arbitrary system commands. The vulnerability requires valid login credentials but poses a meaningful risk to organizations relying on this router model, particularly in environments where user accounts may be compromised or where trust boundaries are weak.

  • CVE-2026-12809MEDIUM 6.3

    A command injection vulnerability exists in Edimax BR-6478AC V2 running firmware 1.23. An authenticated attacker can manipulate the 'newpass' parameter in the wiz_5in1_redirect function to inject arbitrary commands, potentially compromising device integrity and data confidentiality. The vulnerability requires valid login credentials to exploit and is reachable over the network. Public exploit code is available.

  • CVE-2026-12810MEDIUM 6.3

    Edimax BR-6478AC V2 routers running firmware 1.23 contain a command injection vulnerability in their web management interface. An authenticated attacker can manipulate input to the mp endpoint and execute arbitrary system commands on the device. The vulnerability requires valid login credentials but no special privileges, and the exploit code is publicly available.

  • CVE-2026-12813MEDIUM 6.3

    Activepieces versions up to 0.83.0 contain a server-side request forgery (SSRF) vulnerability in the file URL handling component. An authenticated attacker can manipulate file URL processing to cause the server to make unintended requests to internal or external systems. The vulnerability requires valid user credentials to exploit but does not require user interaction. Public exploit code is available, increasing practical risk.

  • CVE-2026-12814MEDIUM 6.3

    Comfast CF-WR631AX V3 routers running firmware version 2.7.0.8 and earlier contain a command injection vulnerability in the ping configuration API endpoint. An authenticated attacker can manipulate the destination parameter to execute arbitrary operating system commands on the router. The vulnerability is remotely exploitable and proof-of-concept code has been published, though the vendor has not engaged on the disclosure or released patches.

  • CVE-2026-12815MEDIUM 6.3

    A vulnerability in Coolify 4.0.0 allows authenticated users to inject operating system commands through the Image Name Handler component. An attacker with valid login credentials could exploit this to execute arbitrary commands on the server hosting Coolify, potentially compromising the entire deployment platform and any applications it manages. The vendor was notified but has not yet released a public response, though version 4.1.2 includes input validation improvements that likely address this issue.

  • CVE-2026-12821MEDIUM 6.3

    FlowiseAI Flowise versions up to 3.1.2 contain a path traversal vulnerability in the S3 Document Loader component. An authenticated attacker can manipulate input to the S3.ts file to access files outside the intended directory structure, potentially exposing sensitive data or interacting with unauthorized resources on the S3 backend. The vulnerability requires valid user credentials but no special privileges to exploit.

  • CVE-2026-13356MEDIUM 6.3

    A flaw in Firefox for iOS allows a malicious webpage to create a deceptive visual state where the address bar shows one website while the page actually displays attacker-controlled content. This happens when a webpage interrupts a normal navigation by triggering a JavaScript dialog box at precisely the right moment. The browser's UI updates to reflect the legitimate destination, but the attacker's content continues to render behind or within that dialog, tricking users into believing they're on a safe site when they're not.

  • CVE-2026-13496MEDIUM 6.3

    CVE-2026-13496 is a SQL injection vulnerability in itsourcecode Hospital Management System version 1.0. An authenticated user can manipulate the medicineid parameter in the /ajaxmedicine.php file to inject malicious SQL commands, potentially allowing them to read, modify, or delete database records. The vulnerability requires login credentials but can be exploited remotely over the network. Public exploit code is available, increasing the practical risk.

  • CVE-2026-13497MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate database queries through the editid parameter in the appointment.php file. An attacker with valid credentials can exploit this flaw to read, modify, or delete sensitive hospital data, including patient records and appointment information. The vulnerability has been publicly disclosed, meaning exploitation guidance may be available to threat actors.

  • CVE-2026-13509MEDIUM 6.3

    RAGapp versions up to 0.1.5 contain a path traversal vulnerability in its file upload and removal functions. An authenticated attacker can manipulate file paths to read, write, or delete files outside the intended knowledge base directory, potentially compromising sensitive data or system integrity. The vulnerability requires login credentials but no special user privileges, and can be exploited over the network.

  • CVE-2026-13512MEDIUM 6.3

    Databend versions up to 1.2.881 contain a flaw in how it manages user sessions over HTTP that allows an authenticated attacker to bypass authorization checks. An attacker with valid credentials can manipulate session state to gain access to resources or actions they should not be permitted to perform. The vulnerability exists in the session state key generation logic and is known to be exploitable; proof-of-concept code is publicly available.

  • CVE-2026-13520MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in its appointment approval handler. An authenticated user can manipulate the 'editid' parameter in the /appointmentapproval.php file to inject SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid login credentials but poses genuine risk to hospitals relying on this system for critical appointment data. Public exploit code is available, raising the urgency of remediation.

  • CVE-2026-13525MEDIUM 6.3

    CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its leave update functionality. An authenticated user can manipulate the employee ID parameter to inject malicious SQL commands, potentially exposing, modifying, or deleting sensitive HR data. The vulnerability has been publicly disclosed and exploitation code is available.

  • CVE-2026-13530MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the 'editid' parameter in the /appointmentdetail.php file to inject malicious SQL commands. This vulnerability allows remote exploitation and could enable an attacker to read, modify, or delete sensitive appointment and patient data. Public exploits are available, increasing the risk of active exploitation.

  • CVE-2026-13531MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the /department.php file. An authenticated attacker can manipulate the editid parameter to execute arbitrary SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. Public exploit code is available, elevating the practical risk.

  • CVE-2026-13532MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in the departmentDoctor.php file that allows authenticated users to execute arbitrary SQL queries by manipulating the deptid parameter. An attacker with valid login credentials can remotely exploit this flaw to read, modify, or delete database records. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-13535MEDIUM 6.3

    CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its employee management interface. An authenticated user can manipulate the ID parameter in the file viewing function to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive HR data. The vulnerability requires valid login credentials but can be exploited remotely without special tools or user interaction.

  • CVE-2026-13538MEDIUM 6.3

    A command injection vulnerability exists in Wavlink WL-NU516U1-A M16U1_V240425 routers. An authenticated attacker can send specially crafted POST requests to the wireless configuration endpoint (/cgi-bin/wireless.cgi) with malicious input in SSID or authentication-related parameters. This allows execution of arbitrary system commands with the privileges of the web server process. The vulnerability requires valid credentials to exploit, but the attack surface is wide since SSID and password parameters are commonly modified during normal router administration.

  • CVE-2026-13540MEDIUM 6.3

    GitBucket versions up to 4.46.1 contain a server-side request forgery (SSRF) vulnerability in how they handle repository clone operations. An authenticated attacker can manipulate the URL argument passed to the repository creation function, causing the GitBucket server to make requests to unintended internal or external systems. The vulnerability requires valid login credentials to exploit but poses a meaningful risk to network confidentiality and integrity.

  • CVE-2026-13541MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0, specifically in the doctor password change functionality. An authenticated user can manipulate the newpassword parameter in /doctorchangepassword.php to inject malicious SQL commands. This allows an attacker to read, modify, or delete database contents without requiring elevated privileges. The vulnerability is remotely exploitable and public exploit code has already been released, increasing the risk of active exploitation.

  • CVE-2026-13542MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in its doctor profile functionality. An authenticated attacker can manipulate the doctorname parameter in /doctorprofile.php to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive healthcare data. The vulnerability requires valid login credentials but can be exploited without user interaction once authenticated. Public disclosure means defensive preparation should be treated as urgent.

  • CVE-2026-13544MEDIUM 6.3

    Feehi CMS versions up to 2.1.1 contain an access control flaw in its API user endpoint that allows authenticated attackers to perform unauthorized actions. An attacker with valid login credentials can bypass intended restrictions and access, modify, or delete user data that should be protected. The vulnerability is remotely exploitable and a proof-of-concept has already been published, increasing the practical risk of exploitation.

  • CVE-2026-13548MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate database queries through the editid parameter in the /doctortimings.php file. An attacker with valid login credentials can exploit this flaw to read, modify, or delete sensitive hospital data. The vulnerability is not yet tracked by CISA's Known Exploited Vulnerabilities catalog, but public exploit code is available, increasing the practical risk of opportunistic attacks.

  • CVE-2026-13560MEDIUM 6.3

    Edimax EW-7478APC wireless access points running firmware version 1.04 contain a command injection flaw in their web interface. An authenticated attacker can manipulate the 'submit-url' parameter sent to the device's configuration handler to execute arbitrary operating system commands. The vulnerability requires valid login credentials but can be exploited remotely over the network. Public details about this flaw are already available, increasing the risk of active exploitation.

  • CVE-2026-13561MEDIUM 6.3

    Edimax EW-7478APC version 1.04 contains a remote command injection vulnerability in its web interface. An authenticated attacker can manipulate the 'rootAPmac' parameter in the formiNICbasic POST request to execute arbitrary operating system commands on the device. The vulnerability has been publicly disclosed, and working exploits are available. The vendor was notified but has not responded or released a patch.

  • CVE-2026-13572MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to execute arbitrary SQL commands by manipulating the patientid parameter in the /insertbillingrecord.php file. An attacker with valid login credentials can exploit this remotely to read, modify, or delete database records. Public disclosure means defensive measures should be prioritized immediately.

  • CVE-2026-13578MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate the editid parameter in the patientdetail.php file, potentially compromising patient data confidentiality and integrity. The vulnerability requires valid login credentials but can be exploited remotely over the network. Public exploit code is already available, increasing the practical risk to deployed instances.

  • CVE-2026-13579MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the password change function to execute arbitrary SQL queries. This allows an attacker with valid login credentials to read, modify, or delete patient data stored in the hospital's database. The vulnerability is in the /patientchangepassword.php file and requires no user interaction beyond the attacker sending a crafted request.

  • CVE-2026-13581MEDIUM 6.3

    Edimax EW-7478APC wireless access point models running firmware version 1.04 contain a remote command injection flaw in the device's web interface. An authenticated attacker can send a specially crafted request to the POST handler at /goform/formStaDrvSetup, manipulating the rootAPmac parameter to execute arbitrary operating system commands on the device. This bypasses the device's normal administrative controls and allows an attacker to fully compromise the access point's security.

  • CVE-2026-13748MEDIUM 6.3

    Snowflake CLI versions before 3.19 contain a path traversal flaw that allows attackers to read arbitrary files from the local system. If an attacker can trick a user into processing malicious project or repository content, the CLI will read files outside the intended project directory and send their contents to Snowflake services. The attacker would then need to access the victim's Snowflake account—such as through query history or uploaded files—to retrieve the exfiltrated data. This requires user interaction and depends on the attacker having follow-on access to the Snowflake environment.

  • CVE-2026-14250MEDIUM 6.3

    The Themehunk Login Registration plugin for WordPress allows unauthenticated users to register new accounts with editor-level permissions when public registration is enabled. The vulnerability exists because the plugin accepts a user-supplied role parameter and validates it against all editable roles—which includes editor—without properly restricting what roles can be assigned during self-registration. An attacker can exploit this by creating an account with editor privileges, granting them significant control over site content and settings.

  • CVE-2026-14604MEDIUM 6.3

    Assimp, an open-source 3D model import/export library widely used in game engines, graphics applications, and CAD tools, contains a memory management flaw in its PLY (Polygon File Format) handler. When exporting 3D models to the PLY format, the library can inadvertently free the same memory region twice—a condition known as a double-free error. An authenticated attacker can trigger this flaw remotely by submitting a specially crafted PLY file, leading to application crash or potential code execution. The vulnerability affects Assimp versions up to and including 6.0.4.

  • CVE-2026-14619MEDIUM 6.3

    A SQL injection vulnerability has been discovered in itsourcecode Hospital Management System version 1.0. An authenticated attacker can manipulate the 'editid' parameter in the /medicine.php file to inject malicious SQL commands. This allows an attacker who has valid login credentials to read, modify, or delete data in the underlying database. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14625MEDIUM 6.3

    NousResearch's hermes-agent, a tool for managing AI agent workflows, contains a vulnerability in how it handles shell execution commands. An authenticated attacker can bypass security controls that normally prevent dangerous operations, potentially gaining the ability to execute arbitrary commands on the affected system. The flaw exists in versions up to 0.15.2 and has already been disclosed publicly with working exploit code available, making it an active risk for organizations using vulnerable deployments.

  • CVE-2026-14638MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient.php file. An authenticated attacker can manipulate the 'editid' parameter to execute arbitrary SQL queries, potentially reading, modifying, or deleting patient data. The vulnerability requires valid login credentials but no additional user interaction, making it exploitable by insiders or through credential compromise. Public exploit code has been released.

  • CVE-2026-14639MEDIUM 6.3

    CodeAstro Ecommerce Website version 1.0 contains a SQL injection vulnerability in its customer account management functionality. An authenticated attacker can manipulate the 'c_name' parameter in the my_account.php?edit_account endpoint to inject malicious SQL commands, potentially compromising data confidentiality, integrity, and availability. Because the vulnerability requires prior authentication and has been publicly disclosed, it presents a moderate but actionable risk that organizations using this software should address promptly.

  • CVE-2026-14657MEDIUM 6.3

    A SQL injection vulnerability has been discovered in code-projects Assessment Management version 1.0. An authenticated attacker can inject malicious SQL code through the squestions[] parameter in the marking-scheme.php file, allowing them to read, modify, or delete database records. The vulnerability requires valid login credentials but does not require user interaction, making it a concern for organizations deploying this assessment platform.

  • CVE-2026-14658MEDIUM 6.3

    A SQL injection vulnerability exists in code-projects Assessment Management version 1.0 that allows authenticated users to manipulate the smarksrange[] parameter in the marking-scheme.php file to execute arbitrary SQL commands. An attacker with valid login credentials can exploit this remotely to read, modify, or delete database records without additional privileges. The vulnerability is already public and proof-of-concept code is available, raising the practical risk despite the medium CVSS score.

  • CVE-2026-14659MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient appointment functionality. An authenticated attacker can inject malicious SQL commands through the 'patiente' parameter in the /patientappointment.php file to read, modify, or delete database records. The vulnerability requires a valid user login but can be exploited remotely, and proof-of-concept details are publicly available.

  • CVE-2026-14689MEDIUM 6.3

    CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its apartment addition function. An authenticated attacker can manipulate the apartment number parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. Proof-of-concept code is publicly available, increasing the likelihood of active exploitation.

  • CVE-2026-14691MEDIUM 6.3

    SourceCodester Multi-Vendor Online Grocery Management System version 1.0 contains a code injection flaw in its settings update functionality. An authenticated attacker can manipulate the content parameter to inject malicious code, which the application will execute. The vulnerability requires login credentials but poses moderate risk due to the simplicity of exploitation and confirmed public disclosure.

  • CVE-2026-14692MEDIUM 6.3

    A SQL injection vulnerability exists in SourceCodester Multi-Vendor Online Grocery Management System versions 1.0 and 5.7.26. An authenticated attacker can inject malicious SQL commands through the POST parameters of the shop type save function, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials but no special privileges, and can be exploited over the network. Public exploit code is available.

  • CVE-2026-14694MEDIUM 6.3

    A SQL injection vulnerability exists in SourceCodester's Multi-Vendor Online Grocery Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the order cancellation function to inject malicious SQL commands. This allows an attacker with valid login credentials to read, modify, or delete database contents. The vulnerability was disclosed publicly, making attack techniques potentially available to a wider audience.

  • CVE-2026-14698MEDIUM 6.3

    SourceCodester's Syllabus-Aligned Learning Management and Examination System version 1.0 contains a file upload vulnerability that allows authenticated users to bypass upload restrictions. An attacker with login credentials can upload arbitrary files to the system, potentially leading to code execution, data theft, or system compromise. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14701MEDIUM 6.3

    A SQL injection vulnerability exists in the Internship Management System version 1.0, specifically in the password change function. An authenticated user can manipulate the 'Current' parameter to inject malicious SQL commands, potentially accessing or modifying sensitive data in the database. The vulnerability requires login credentials but is otherwise straightforward to exploit, and proof-of-concept code is already publicly available.

  • CVE-2026-14703MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate the editid parameter in the /patientorder.php file to execute arbitrary SQL queries. The vulnerability requires valid login credentials to exploit but does not require user interaction once authenticated. Public disclosure of this vulnerability means exploitation techniques are already available to potential attackers.

  • CVE-2026-14706MEDIUM 6.3

    A SQL injection vulnerability exists in code-projects Online Examination 1.0 affecting the quiz creation feature. An authenticated attacker can manipulate multiple input fields (name, total, right, wrong, time, tag, desc) in the /update.php?q=addquiz endpoint to inject malicious SQL commands. This allows unauthorized data access, modification, or deletion within the application's database. The vulnerability requires valid login credentials but can be exploited remotely with no user interaction.

  • CVE-2026-14716MEDIUM 6.3

    A flaw in nextlevelbuilder GoClaw's WebSocket RPC handler allows authenticated users to bypass authorization checks and gain unauthorized access to protected functionality. An attacker with valid credentials can exploit the MethodRouter.Handle function to perform actions they should not have permission to execute, including reading sensitive data or modifying system state. The vulnerability affects versions up to 3.13.0-beta.2 and has been publicly disclosed.