5.1

CVSS4.0

CVE-2026-0698 - code-projects Intern Membership Management System edit_students.php sql injection

A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown function of the file /intern/admin/edit_students.php. Such manipulation of the argument admin_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 5:32 a.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 3:51 p.m.

5.1

CVSS4.0

CVE-2026-0697 - code-projects Intern Membership Management System edit_admin.php sql injection

A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown function of the file /intern/admin/edit_admin.php. This manipulation of the argument admin_id causes sql injection. The attack may be initiated remotely. The exploit has been publishedโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 4:32 a.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 3:51 p.m.

8.5

CVSS4.0

CVE-2026-21427 -

The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running installer.

๐Ÿ“… Published: Jan. 8, 2026, 4:12 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 4:12 a.m.

9.8

CVSS3.1

CVE-2019-25296 - WP Cost Estimation <= 9.642 - Missing Authorization to Arbitrary File Upload/Delete

The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_upload_form and lfb_removeFile AJAX actions in versions up to, and including, 9.642. This makes it possible for unauthenticated attackers to upload arbitraโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 2:21 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 2:21 a.m.

4.3

CVSS3.1

CVE-2025-12640 - Folders โ€“ Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 -โ€ฆ

The Folders โ€“ Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Replacement in all versions up to, and including, 3.1.5. This is due to missing object-level authorization checks in the handle_folders_filโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 2:21 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 2:21 a.m.

6.4

CVSS3.1

CVE-2025-14275 - Jeg Elementor Kit <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdownโ€ฆ

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.0.1 due to insufficient input sanitization in the countdown widget's redirect functionality. This makes it possible for authenticated attackers, with Contributor-level accโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 2:21 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 2:21 a.m.

6.5

CVSS3.1

CVE-2019-25295 - WP Cost Estimation < 9.660 - Upload Directory Traversal

The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. This allows attackers to overwrite any file with a whitelisted type on an affected site.

๐Ÿ“… Published: Jan. 8, 2026, 1:50 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 1:50 a.m.

4.5

CVSS4.0

CVE-2026-21883 - Bokeh server applications have Incomplete Origin Validation in WebSockets

Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured with an allowlist (e.g., dashboard.corp), an attacker can register a domain like dashboard.corp.attacker.com (or use a subdomain if applicable) and lure a victim to visit it. The โ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 1:20 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 1:20 a.m.

9.1

CVSS3.1

CVE-2026-21881 - Kanboard is Vulnerable to Reverse Proxy Authentication Bypass

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a โ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 1:08 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 1:08 a.m.

5.3

CVSS3.1

CVE-2026-21880 - Kanboard LDAP Injection Vulnerability can Lead to User Enumeration and Information Disclosure

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumeraโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 12:59 a.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 12:59 a.m.
Total resulsts: 327160
Page 53 of 32,716
ยซ previous page ยป next page
Filters