VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

348 CVEsRSS

CVE-2026-93742Critical· 9.9
2d ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be init…

MidnightTotolink · A3002MUEPSS 1.9%via NVD
CVE-2026-87909High· 7.5
2d ago

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into a…

Twilightopajaap · WP Photo Album PlusEPSS 0.53%via NVD
CVE-2026-93371High· 8.3
3d ago

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads t…

Twilightmarcopiovanello · yt-dlp-web-uiEPSS 1.4%via NVD
CVE-2026-87701Critical· 9.6
4d ago

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure Cosmos DBEPSS 0.44%via NVD
CVE-2026-92926High· 7.3PoC
4d ago

A vulnerability has been found in code-projects Matrimonial System 1.0

A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. Th…

Midnightcode-projects · Matrimonial SystemEPSS 0.27%via NVD
CVE-2026-93295Medium· 5.1
4d ago

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher:…

Sunlitmisp · mispEPSS 0.50%via NVD
CVE-2026-92526Medium· 6.3
5d ago

A flaw has been found in itsourcecode Leave Management System 1.0

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched re…

Sunlititsourcecode · Leave Management SystemEPSS 0.20%via NVD
CVE-2026-92406High· 7.3PoC
5d ago

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argum…

MidnightSourceCodester · Inventory and Monitoring SystemEPSS 0.41%via NVD
CVE-2026-92405High· 7.3PoC
5d ago

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The …

MidnightSourceCodester · Inventory and Monitoring SystemEPSS 0.41%via NVD
CVE-2026-20130Critical· 10.0
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal secur…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal secur…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.40%via NVD
CVE-2026-90999Critical· 9.8
5d ago

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can su…

MidnightFunctional Software, Inc. · Sentry SeerEPSS 0.51%via NVD
CVE-2026-92366High· 7.3PoC
5d ago

A vulnerability was determined in code-projects Matrimonial System 1.0

A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state…

Midnightcode-projects · Matrimonial SystemEPSS 0.48%via NVD
CVE-2026-92132Medium· 5.4
5d ago

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able…

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able…

SunlitJenkins Project · Jenkins Gradle PluginEPSS 0.24%via NVD
CVE-2026-92364Medium· 6.3PoC
5d ago

A vulnerability has been found in itsourcecode Leave Management System 1.0

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It…

Twilightitsourcecode · Leave Management SystemEPSS 0.32%via NVD
CVE-2026-19857Medium· 4.8PoC
5d ago

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to…

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to…

TwilightEPSS 0.19%via NVD
CVE-2026-92221Medium· 4.7
5d ago

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_global_admin_model.p…

Sunlitgedelumbung · HospitalManagementEPSS 0.27%via NVD
CVE-2026-92213Medium· 5.5
5d ago

A vulnerability was detected in a2ui-project a2ui up to 0.10.6

A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argume…

Sunlita2ui-project · a2uiEPSS 0.24%via NVD
CVE-2026-12351Critical· 9.8
6d ago

IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when th…

IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when th…

MidnightIBM · MQEPSS 0.86%via NVD
CVE-2026-12355High· 8.1
6d ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI i…

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI i…

TwilightIBM · MQEPSS 0.38%via NVD
CVE-2026-11927Medium· 6.5
6d ago

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

SunlitIBM · Verify Identity AccessEPSS 0.17%via NVD
CVE-2026-91848High· 7.3PoC
6d ago

A vulnerability was identified in WuzhiCMS up to 4.1.0

A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads t…

MidnightEPSS 0.46%via NVD
CVE-2026-91986Medium· 5.4
6d ago

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof …

SunlitGitoxideLabs · gitoxideEPSS 0.20%via NVD
CVE-2026-91004High· 7.3PoC
6d ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack c…

MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.26%via NVD
CVE-2026-90880High· 7.4PoC
6d ago

A security flaw has been discovered in D-Link DSL-3782 2016-07-28

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr resul…

MidnightD-Link · DSL-3782EPSS 1.0%via NVD
CVE-2026-90879High· 7.3PoC
6d ago

A vulnerability was identified in zyx0814 FilePress up to 3.0.1

A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql inj…

Midnightzyx0814 · FilePressEPSS 0.26%via NVD
CVE-2026-90877High· 7.3PoC
6d ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injec…

MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.26%via NVD
CVE-2026-90876High· 7.3PoC
6d ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql inject…

MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.27%via NVD
CVE-2026-90855High· 7.3PoC
6d ago

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be init…

MidnightSourceCodester · Online Food Ordering SystemEPSS 0.26%via NVD
CVE-2026-90854High· 7.3
6d ago

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injec…

TwilightSourceCodester · Online Food Ordering SystemEPSS 0.26%via NVD
CVE-2026-90849High· 7.3PoC
6d ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User le…

MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.27%via NVD
CWE-74 vulnerabilities (CVEs) — page 2 · VulnSea