| CVE-2026-26708 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. | critical | 2026-03-03 |
| CVE-2026-26700 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php. | critical | 2026-03-03 |
| CVE-2026-24105 | An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd. | critical | 2026-03-06 |
| CVE-2026-23865 | An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2. | medium | 2026-03-04 |
| CVE-2026-21385 | Memory corruption while using alignments for memory allocation. | high | 2026-03-04 |
| CVE-2025-70252 | An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability. | high | 2026-03-06 |
| CVE-2025-64427 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0.1, localhost, or private network ranges). This allows the attacker to interact with internal HTTP/HTTPS services that are not intended to be exposed externally or to local users. No known patch is publicly available. | medium | 2026-03-05 |
| CVE-2025-59603 | Memory Corruption when processing invalid user address with nonstandard buffer address. | high | 2026-03-04 |
| CVE-2025-59600 | Memory Corruption when adding user-supplied data without checking available buffer space. | high | 2026-03-03 |
| CVE-2025-47386 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. | high | 2026-03-05 |
| CVE-2025-47385 | Memory Corruption when accessing trusted execution environment without proper privilege check. | high | 2026-03-05 |
| CVE-2025-47384 | Transient DOS when MAC configures config id greater than supported maximum value. | medium | 2026-03-05 |
| CVE-2025-47383 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | high | 2026-03-04 |
| CVE-2025-47381 | Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs. | high | 2026-03-04 |
| CVE-2025-47379 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | high | 2026-03-05 |
| CVE-2025-47378 | Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. | high | 2026-03-05 |
| CVE-2025-47377 | Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls. | high | 2026-03-04 |
| CVE-2025-47376 | Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls. | high | 2026-03-04 |
| CVE-2025-47375 | Memory corruption while handling different IOCTL calls from the user-space simultaneously. | high | 2026-03-04 |
| CVE-2025-47373 | Memory Corruption when accessing buffers with invalid length during TA invocation. | high | 2026-03-04 |
| CVE-2025-47371 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | medium | 2026-03-04 |
| CVE-2026-28412 | Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server with connections, causing the Textream application to freeze and crash during a live session. Version 1.5.1 fixes the issue. | high | 2026-03-10 |
| CVE-2026-28403 | Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without validating the HTTP `Origin` header during the WebSocket handshake. A malicious web page visited in the same browser session can silently connect to the local WebSocket server and send arbitrary `DirectorCommand` payloads, allowing full remote control of the teleprompter content. Version 1.5.1 fixes the issue. | high | 2026-03-10 |
| CVE-2026-26720 | An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module. | critical | 2026-03-04 |
| CVE-2026-26701 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php. | critical | 2026-03-03 |
| CVE-2026-26699 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php. | high | 2026-03-04 |
| CVE-2026-24112 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addWewifiWhiteUser` function and processed by `sscanf` without size validation, it could lead to a buffer overflow vulnerability. | critical | 2026-03-03 |
| CVE-2026-24110 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule, " %d\t%[^\t]\t%[^\n\r\t]", &dhcpsIndex, dhcpsIP, dhcpsMac);`, the lack of size validation for the rules could lead to buffer overflows in `dhcpsIndex`, `dhcpsIP`, and `dhcpsMac`. | critical | 2026-03-03 |
| CVE-2026-24101 | An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability. | critical | 2026-03-03 |
| CVE-2026-0689 | In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear redacted in the user interface, the application returns the underlying credential values in the HTTP response, enabling an authorized administrator to recover stored secrets that may exceed their intended access. We would like to thank the Lockheed Martin Red Team for responsibly reporting this issue and working with us through coordinated disclosure. | high | 2026-03-02 |
| CVE-2025-66880 | Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute arbitrary code via the LoginComp (Module 2093) and SignupComp (Module 2094) modules. | medium | 2026-03-02 |
| CVE-2025-52998 | Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and thus modify the logic of the web application's operation. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2025-52564 | Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been patched in version 1.11.30. | medium | 2026-03-03 |
| CVE-2025-52563 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/add_users_to_session.php endpoint. This issue has been patched in version 1.11.30. | medium | 2026-03-03 |
| CVE-2025-52476 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the keyword_active parameter in admin/user_list.php. This issue has been patched in version 1.11.30. | medium | 2026-03-03 |
| CVE-2025-52475 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability in the admin/user_list.php endpoint. The keyword_inactive parameter is not properly sanitized, allowing attackers to inject malicious JavaScript through a crafted URL. This issue has been patched in version 1.11.30. | medium | 2026-03-03 |
| CVE-2025-52470 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by improper sanitization of the Category Name field, allowing privileged users to inject persistent JavaScript payloads. The injected script is later executed when accessing add_many_sessions_to_category.php, potentially compromising administrative sessions. This issue has been patched in version 1.11.30. | medium | 2026-03-03 |
| CVE-2025-52469 | Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX endpoint. The attacker can bypass the normal flow of sending and accepting friend requests, and even add non-existent users. This breaks access control and social interaction logic, with potential privacy implications. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2025-52468 | Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "First Name", and "Username" fields. It allows attackers to inject a stored cross-site scripting (XSS) payload that is triggered when the user profile is viewed, potentially leading to malicious script execution in the context of the authenticated use. This issue has been patched in version 1.11.30. | medium | 2026-03-03 |
| CVE-2025-50199 | Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2025-50198 | Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2025-50197 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2025-50196 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2025-50195 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2025-50194 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2025-50193 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30. | high | 2026-03-03 |
| CVE-2026-26703 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php. | critical | 2026-03-03 |
| CVE-2026-26702 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php. | critical | 2026-03-03 |
| CVE-2026-26696 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php. | critical | 2026-03-03 |
| CVE-2026-26695 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php. | critical | 2026-03-05 |