Common Vulnerabilities and Exposures (CVE)

CVE-2026-3006

Apr 27, 2026 02:35:17 UTC

Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software.

CVE-2026-7079

Apr 27, 2026 02:30:15 UTC

A weakness has been identified in Tenda F456 1.0.0.5. This affects the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. This manipulation of the argument wanmode causes buffer overflow. The attack may be initiate...

CVE-2026-7106

Apr 27, 2026 02:26:24 UTC

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is h...

CVE-2026-7078

Apr 27, 2026 02:15:12 UTC

A security flaw has been discovered in Tenda F456 1.0.0.5. The impacted element is the function fromSetIpBind of the file /goform/SetIpBind of the component httpd. The manipulation of the argument page results in buffer overflow. The attack...

CVE-2026-5201

Apr 27, 2026 02:08:56 UTC

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker...

CVE-2026-7077

Apr 27, 2026 02:00:21 UTC

A vulnerability was identified in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /edit_parcel.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated ...

CVE-2026-7076

Apr 27, 2026 01:45:11 UTC

A vulnerability was determined in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /edit_branch.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the ...

CVE-2026-7075

Apr 27, 2026 01:30:31 UTC

A vulnerability was found in itsourcecode Construction Management System 1.0. This issue affects some unknown processing of the file /locations.php. Performing a manipulation of the argument address results in sql injection. It is possible ...

CVE-2026-7074

Apr 27, 2026 01:15:14 UTC

A vulnerability has been found in itsourcecode Construction Management System 1.0. This vulnerability affects unknown code of the file /execute1.php. Such manipulation of the argument code leads to sql injection. The attack may be performed...

CVE-2026-7073

Apr 27, 2026 01:00:20 UTC

A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /execute.php. This manipulation of the argument code causes sql injection. The attack is possible to be carried out remotely....

CVE-2026-7072

Apr 27, 2026 00:45:10 UTC

A vulnerability was detected in CodePanda Source canteen_management_system 1.0. Affected by this issue is some unknown functionality of the file /api/login.php. The manipulation of the argument Username results in sql injection. The attack ...

CVE-2026-7071

Apr 27, 2026 00:30:11 UTC

A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remot...

CVE-2026-7070

Apr 27, 2026 00:15:12 UTC

A weakness has been identified in code-projects Inventory Management System 1.0. Affected is an unknown function of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched...

CVE-2026-33566

Apr 27, 2026 00:04:23 UTC

There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.

CVE-2026-33277

Apr 27, 2026 00:03:41 UTC

An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.