1.3
CVE-2025-44013 - QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versiβ¦
2.2
CVE-2025-62857 - QuMagie
A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QuMagie 2.8.1 and later
5.1
CVE-2025-15438 - PluXml Media Management medias.php __destruct deserialization
A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the argument File can lead to deserialization. The attack can be launched remotely. The eβ¦
6.9
CVE-2026-0565 - code-projects Content Management System delete.php sql injection
A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing a manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available tβ¦
5.3
CVE-2026-0547 - PHPGurukul Online Course Registration Student Registration edit-student-profile.php unrestricted upβ¦
A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profile.php of the component Student Registration Page. The manipulation of the argument photo results in unrestricted upload. The attack may be lβ¦
6.9
CVE-2026-0546 - code-projects Content Management System search.php sql injection
A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipulation of the argument Value causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may beβ¦
0.0
CVE-2026-21645 -
Not used
0.0
CVE-2026-21651 -
Not used
0.0
CVE-2026-21647 -
Not used
0.0
CVE-2026-21650 -
Not used