VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

348 CVEsRSS

CVE-2026-85113Medium· 6.5
today

The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated …

The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated …

SunlitEPSS 0.18%via NVD
CVE-2026-94144High· 7.3
today

A flaw has been found in drogonframework drogon up to 1.9.13

A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. …

Twilightdrogonframework · drogonEPSS 0.25%via NVD
CVE-2026-94143High· 7.3PoC
today

A vulnerability was detected in drogonframework drogon up to 1.9.13

A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sq…

Midnightdrogonframework · drogonEPSS 0.25%via NVD
CVE-2026-94139High· 7.4
today

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation o…

TwilightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 1.2%via NVD
CVE-2026-94138Medium· 6.6PoC
today

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac result…

TwilightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 2.1%via NVD
CVE-2026-94110High· 7.3
today

A security vulnerability has been detected in QCMS up to 6.0.6

A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql in…

TwilightEPSS 0.26%via NVD
CVE-2026-94103Medium· 4.7PoC
today

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the argument content leads to code injection.…

TwilightEPSS 0.24%via NVD
CVE-2026-94099Critical· 9.9
today

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results…

MidnightNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94098Critical· 9.1PoC
today

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING…

AbyssalNetcore · NBR200V2EPSS 2.4%via NVD
CVE-2026-94097Critical· 10.0
today

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes co…

MidnightNetcore · NBR200V2EPSS 2.0%via NVD
CVE-2026-94096Critical· 9.9PoC
today

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…

AbyssalNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94095Critical· 9.9
today

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the a…

MidnightNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94042Medium· 6.3
yesterday

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The manipulation of the argument table/membe…

SunlitAdithyaYelloju · Restaurant Management SystemEPSS 0.19%via NVD
CVE-2026-94041Medium· 6.3PoC
yesterday

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the ar…

TwilightAdithyaYelloju · Restaurant-Management-SystemEPSS 0.20%via NVD
CVE-2026-94032Medium· 6.3
yesterday

A flaw has been found in itsourcecode Leave Management System 1.0

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack re…

Sunlititsourcecode · Leave Management SystemEPSS 0.20%via NVD
CVE-2026-94031Medium· 6.3PoC
yesterday

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool. The manipula…

Twilight0-Gaurav-0 · nexus-mcpEPSS 1.1%via NVD
CVE-2026-94015High· 7.3
yesterday

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user.php. Such manipulation of the argument ID leads to sql injection. The attack …

TwilightSourceCodester · Drug Recommendation SystemEPSS 0.26%via NVD
CVE-2026-94004High· 7.3PoC
yesterday

A vulnerability was found in DedeCMS up to 5.7.118

A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The explo…

MidnightEPSS 0.30%via NVD
CVE-2026-93997High· 7.3
yesterday

A weakness has been identified in SourceCodester Drug Recommendation System 1.0

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The att…

TwilightSourceCodester · Drug Recommendation SystemEPSS 0.26%via NVD
CVE-2026-93980High· 7.3
yesterday

A weakness has been identified in code-projects Internship Management System 1.0

A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password c…

Twilightcode-projects · Internship Management SystemEPSS 0.26%via NVD
CVE-2026-93979High· 7.3
yesterday

A security flaw has been discovered in code-projects Internship Management System 1.0

A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of the argument Password results in sql injection. The attack …

Twilightcode-projects · Internship Management SystemEPSS 0.26%via NVD
CVE-2026-93978High· 7.3
yesterday

A vulnerability was identified in code-projects Internship Management System 1.0

A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack …

Twilightcode-projects · Internship Management SystemEPSS 0.26%via NVD
CVE-2026-93974High· 7.3
yesterday

A flaw has been found in SourceCodester Online Reviewer Management System 1.0

A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of the argument…

TwilightSourceCodester · Online Reviewer Management SystemEPSS 0.33%via NVD
CVE-2026-93973High· 7.3
yesterday

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulati…

TwilightSourceCodester · Online Reviewer Management SystemEPSS 0.26%via NVD
CVE-2026-93972High· 7.3
yesterday

A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0

A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the…

TwilightSourceCodester · Online Reviewer Management SystemEPSS 0.27%via NVD
CVE-2026-93966Medium· 4.7
yesterday

A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1

A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. Such manipulation of th…

Sunlitaiyiyi121 · SxDevOpsEPSS 1.6%via NVD
CVE-2026-93967Medium· 5.5
yesterday

A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1

A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command …

Sunlitaiyiyi121 · SxDevOpsEPSS 0.73%via NVD
CVE-2026-93963Medium· 6.3
yesterday

A security vulnerability has been detected in itsourcecode Leave Management System 1.0

A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The a…

Sunlititsourcecode · Leave Management SystemEPSS 0.20%via NVD
CVE-2026-93965Medium· 6.6
yesterday

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpoint_or_command caus…

Sunlitaiyiyi121 · SxDevOpsEPSS 1.6%via NVD
CVE-2026-93959High· 7.3
yesterday

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Cou…

TwilightSourceCodester · Online Reviewer Management SystemEPSS 0.36%via NVD
CWE-74 vulnerabilities (CVEs) · VulnSea