TROYANOSYVIRUS

Vulnerabilidades CVE

Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD

Total: 6,282 CVEs
CVE IDCVSSSeveridadKEVAvistamientos
CVE-2026-36232

A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['c...

9.8CRITICALβ€”0
CVE-2026-36233

A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious...

9.8CRITICALβ€”0
CVE-2026-36235

A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly em...

9.8CRITICALβ€”0
CVE-2026-36236

SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.

9.8CRITICALβ€”0
CVE-2026-27460

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functiona...

6.5MEDIUMβ€”0
CVE-2026-36922

Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category.php.

2.7LOWβ€”0
CVE-2026-36923

Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php.

2.7LOWβ€”0
CVE-2025-63939

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.

9.8CRITICALβ€”0
CVE-2026-38528

Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php.

7.1HIGHβ€”0
CVE-2026-38529

A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a ful...

8.8HIGHβ€”0
CVE-2026-0207

A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.

N/ANONEβ€”0
CVE-2026-0209

Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured.

N/ANONEβ€”0
CVE-2026-0390

Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

6.7MEDIUMβ€”0
CVE-2026-20806

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

5.5MEDIUMβ€”0
CVE-2026-20928

Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.

4.6MEDIUMβ€”0
CVE-2026-20930

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

7.8HIGHβ€”0
CVE-2025-70023

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

9.8CRITICALβ€”0
CVE-2026-20945

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

4.6MEDIUMβ€”0
CVE-2026-23657

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8HIGHβ€”0
CVE-2026-26173

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally...

7.0HIGHβ€”0
CVE-2026-26174

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

7.0HIGHβ€”0
CVE-2026-26175

Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.

4.6MEDIUMβ€”0
CVE-2026-26176

Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally.

7.8HIGHβ€”0
CVE-2026-27258

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to corrupt ...

5.5MEDIUMβ€”0
CVE-2026-27906

Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

4.4MEDIUMβ€”0
CVE-2026-27907

Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

7.8HIGHβ€”0
CVE-2026-27908

Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.

7.0HIGHβ€”0
CVE-2026-32080

Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.

7.0HIGHβ€”0
CVE-2026-32189

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8HIGHβ€”0
CVE-2026-33114

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.4HIGHβ€”0
CVE-2026-33115

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.4HIGHβ€”0
CVE-2026-33116

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

7.5HIGHβ€”0
CVE-2026-33120

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

8.8HIGHβ€”0
CVE-2026-33822

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

6.1MEDIUMβ€”0
CVE-2026-33824

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

9.8CRITICALβ€”0
CVE-2026-33825

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

7.8HIGHβ€”0
CVE-2026-33826

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

8.0HIGHβ€”0
CVE-2016-20053

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting m...

5.3MEDIUMβ€”0
CVE-2016-20055

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a ma...

7.8HIGHβ€”0
CVE-2026-34783

Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library function allows a malicious website to write...

8.1HIGHβ€”0
CVE-2026-35036

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link preview (editor fetches a page title) through GET /api/website/title. That is le...

7.5HIGHβ€”0
CVE-2026-35489

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from requ...

7.3HIGHβ€”0
CVE-2026-31040

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.

9.8CRITICALβ€”0
CVE-2026-33229

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script ...

9.8CRITICALβ€”0
CVE-2023-46945

QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request

9.1CRITICALβ€”0
CVE-2026-34578

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_...

8.2HIGHβ€”0
CVE-2026-5440

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value witho...

7.5HIGHβ€”0
CVE-2026-5441

An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression forma...

7.1HIGHβ€”0
CVE-2026-40168

Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct pr...

8.2HIGHβ€”0
CVE-2026-40188

goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the ...

7.7HIGHβ€”0
Pagina 113 de 126

This product uses data from the NVD API but is not endorsed or certified by the NVD.