Common Vulnerabilities and Exposures (CVE)

CVE-2026-2060

Feb 6, 2026 17:32:07 UTC

A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Performing a manipulation of the argument ID...

CVE-2022-40924

Feb 6, 2026 17:28:06 UTC

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.

CVE-2026-23741

Feb 6, 2026 17:26:22 UTC

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on line 689 of...

CVE-2025-5553

Feb 6, 2026 17:21:36 UTC

A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download-pass.php. The manipulation of the argument searchdata leads to ...

CVE-2026-1769

Feb 6, 2026 17:20:16 UTC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare...

CVE-2023-6425

Feb 6, 2026 17:16:22 UTC

A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/medical_records_view.php, in the FirstRecord parameter...

CVE-2026-1499

Feb 6, 2026 17:10:58 UTC

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combi...

CVE-2026-1785

Feb 6, 2026 17:07:58 UTC

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download and update actions in the Cloud_Search_Lis...

CVE-2022-44151

Feb 6, 2026 17:06:32 UTC

Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

CVE-2026-24926

Feb 6, 2026 17:06:22 UTC

Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

CVE-2026-1252

Feb 6, 2026 17:05:06 UTC

The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it ...

CVE-2026-24919

Feb 6, 2026 17:05:04 UTC

Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.

CVE-2026-24914

Feb 6, 2026 17:02:11 UTC

Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

CVE-2026-2059

Feb 6, 2026 17:02:07 UTC

A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be perform...

CVE-2025-64111

Feb 6, 2026 16:58:01 UTC

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve remote command execution. This issue has be...