Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2019-25481

8.8

iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the …

iScripts
Details

CVE-2019-25479

8.8

Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the …

Inout
Details

CVE-2019-25473

7.1

Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month parameter. Attackers can send POST requests to the …

Clinic
Details

CVE-2026-4042

7.4

A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index causes stack-based buffer overflow. …

Details

CVE-2026-4041

7.4

A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. …

Details

CVE-2026-28384

9.4

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to …

An
Details

CVE-2026-21671

9.1

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

Veeam
Details

CVE-2026-21670

6.5

A vulnerability allowing a low-privileged user to extract saved SSH credentials.

Veeam
Details

CVE-2026-21669

9.9

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Veeam
Details

CVE-2026-21668

6.5

A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

Veeam
Details
683/3864