Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)

Latest Security News

Recently analyzed articles from 41 RSS feeds across official advisories, government CERTs, security research, and community sources.

Tier A: Official
Tier B: Gov CERT
Tier C: Research
Tier D: News
Tier E: Community
Status:
AllAnalyzedQueuedSignal Only
C
CVE-2026-78246 | itsourcecode Online Clinic Management System 1.0 Admin Login success/login.php Username sql injection
VulDB·41m ago·cve_linking
C
CVE-2026-78245 | itsourcecode Online Pharmacy System 1.0 User Registration all_users/register.php move_uploaded_file photo unrestricted upload
VulDB·55m ago·cve_linking
C
CVE-2026-78244 | itsourcecode Real Estate Management System 1.0 search.php search/delivery_type/search_price/property_type sql injection
VulDB·1h ago·cve_linking
C
CVE-2026-78202 | itsourcecode Payroll System 1.0 admin_class.php save_settings img unrestricted upload
VulDB·7h ago·cve_linking
C
CVE-2026-78201 | itsourcecode Payroll System 1.0 admin_class.php login Username sql injection
VulDB·7h ago·cve_linking
C
CVE-2026-78200 | itsourcecode Library Management System 1.0 editbooks.php ID sql injection
VulDB·7h ago·cve_linking
C
CVE-2026-78199 | SourceCodester Simple Online Food Ordering System 1.0 /fos/view_prod.php ID sql injection
VulDB·7h ago·cve_linking
C
CVE-2026-78198 | SourceCodester Simple Online Food Ordering System 1.0 ajax.php?action=add_to_cart pid sql injection
VulDB·7h ago·cve_linking
C
CVE-2026-78197 | SourceCodester Simple Online Food Ordering System 1.0 ajax.php?action=save_user Username sql injection
VulDB·7h ago·cve_linking
C
CVE-2026-78196 | achorein expo-share-intent up to 8.0.0 Android File Copy Routine ExpoShareIntentModule.kt getDataColumn _display_name path traversal (ID 221)
VulDB·8h ago·cve_linking
C
CVE-2026-78187 | Piwigo 16.3.0 Public Authentication Page lang cross site scripting (GHSA-rr39-mf4j-6594)
VulDB·13h ago·cve_linking
C
CVE-2026-78186 | Open5GS up to 2.8.0 HSS src/hss/hss-cx-path.c User-Name assertion (Issue 4675)
VulDB·13h ago·cve_linking
C
CVE-2026-78185 | itsourcecode Sales and Inventory System 1.0 /pages/cust_edit.php ID sql injection
VulDB·13h ago·cve_linking
C
CVE-2026-78182 | Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300 plansImmediate PlanController.getImmediatePlans order/sort sql injection
VulDB·13h ago·cve_linking
C
CVE-2026-78181 | ractivejs ractive up to 1.4.4 Keypath Ractive#set prototype pollution (Issue 3448)
VulDB·14h ago·cve_linking
C
CVE-2026-78180 | alibaba-fusion next up to 1.27.34 deepMerge index.tsx ConfigProvider.getContextProps locale prototype pollution (Issue 5101)
VulDB·14h ago·cve_linking
C
CVE-2026-78179 | rexrainbow phaser3-rex-notes up to 1.80.17 BehaviorTree Blackboard Data Interface SetValue.js SetValue key prototype pollution (Issue 572)
VulDB·14h ago·cve_linking
C
CVE-2026-78178 | jQWidgets up to 24.0.1 jqwidgets/jqx-all.js JQXLite.extend/jqxBaseFramework.extend prototype pollution (Issue 764)
VulDB·14h ago·cve_linking
C
CVE-2026-78177 | TanStack devtools-vite 0.7.0 Development Devtools Event Bus package-manager.ts installPackage packageName os command injection (Issue 464)
VulDB·14h ago·cve_linking
C
CVE-2026-78171 | itsourcecode Sales and Inventory System 1.0 /pages/processlogin.php User sql injection
VulDB·15h ago·cve_linking
C
CVE-2026-78170 | UTT HiPER 1200GW up to 2.5.3-170306 formConfigFastDirectionW strcpy ssid buffer overflow
VulDB·16h ago·cve_linking
C
CVE-2026-78169 | UTT HiPER 1250GW up to 3.2.7-210907-180535 HTTP Request aspRemoteApConfTempSend strcpy Profile stack-based overflow
VulDB·16h ago·cve_linking
C
CVE-2026-78168 | EFM ipTIME T24000M up to 14.20.0 Session Validation httpcon_check_session_url improper authentication
VulDB·16h ago·cve_linking
C
CVE-2026-78167 | EFM ipTIME T16000M 14.20.2 Session Validation httpcon_check_session_url improper authentication
VulDB·16h ago·cve_linking
C
CVE-2026-78166 | provectus kafka-ui up to 0.7.2 Groovy Code MessagesController.java executeSmartFilterTest code injection (Issue 4567)
VulDB·16h ago·cve_linking
C
CVE-2026-78161 | warmcat libwebsockets 4.5.0 LECP CBOR Recording lib/misc/lecp.c report_raw_cbor out-of-bounds write
VulDB·18h ago·cve_linking
C
CVE-2026-78160 | Dolibarr ERP up to 18.0.10/22.0.5/23.0.3 User Notes /user/note.php ID authorization (Issue 39063)
VulDB·18h ago·cve_linking
C
CVE-2026-78158 | Open5GS 2.8.0 AMF UEContextReleaseRequest Path improper authorization (GHSA-mg8r-2cvv-xq9j)
VulDB·18h ago·cve_linking
C
CVE-2026-78157 | Open5GS 2.8.0 Rx AA-Request src/pcrf/pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds (Issue 4663)
VulDB·18h ago·cve_linking
C
CVE-2026-78156 | Open5GS 2.8.0 S6a Authentication-Information-Request src/hss/hss-s6a-path.c hss_ogs_diam_s6a_air_cb Visited-PLMN-Id heap-based overflow (Issue 4661)
VulDB·18h ago·cve_linking
C
CVE-2026-78154 | the-momentum open-wearables up to 0.6.2 Public Invitation-Code Redemption Endpoint user_invitation_code.py redeem_invitation_code missing authentication
VulDB·22h ago·cve_linking
C
CVE-2026-78148 | ggml-org llama.cpp bec4772f6 ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereference (Issue 25299)
VulDB·23h ago·cve_linking
C
CVE-2026-78145 | CTFd up to 3.8.4 __init__.py _is_safe_url Next redirect
VulDB·23h ago·cve_linking
C
CVE-2026-78144 | code-projects Barangay Resident Profiling Management System 1.0 Boarder Management /boarders.php ID authorization
VulDB·1d ago·cve_linking
C
CVE-2026-78143 | code-projects Barangay Resident Profiling Management System 1.0 Resident Search Functionality residents.php sql injection
VulDB·1d ago·cve_linking
C
CVE-2026-78142 | code-projects Barangay Resident Profiling Management System 1.0 Restore/Delete /archived_records.php resident_id authorization
VulDB·1d ago·cve_linking
C
CVE-2026-78141 | Tenda CH22 1.0.0.1 /goform/exeCommand formexeCommand cmdinput command injection
VulDB·1d ago·cve_linking
C
CVE-2026-78140 | Dromara UJCMS up to 10.1.3 web-file-template Endpoint WebFileTemplateController.java update special elements in template engine
VulDB·1d ago·cve_linking
C
CVE-2026-78115 | SourceCodester Class and Exam Timetabling System 1.0 User Account Update edit_user_account.php id/username improper authorization
VulDB·1d ago·cve_linking
C
CVE-2026-78112 | itsourcecode Hospital Management System Project in PHP 1.0 /viewservicetype.php delid sql injection
VulDB·1d ago·cve_linking
C
CVE-2026-78063 | Tenda CH22 1.0.0.1 /goform/editFileName formeditFileName editNameMit command injection
VulDB·1d ago·cve_linking
C
CVE-2026-78062 | vas3k TaxHacker up to 0.8.2 JWT Secret lib/config.ts envSchema.parse BETTER_AUTH_SECRET hard-coded credentials
VulDB·1d ago·cve_linking
C
CVE-2026-78061 | vas3k TaxHacker up to 0.8.2 Email Sync imap-client.ts buildImapConfig host/port server-side request forgery (Issue 148)
VulDB·1d ago·cve_linking
C
CVE-2026-78060 | SourceCodester Stock Management System 1.0 getOrderReport.php clientName/clientContact cross site scripting
VulDB·1d ago·cve_linking
C
CVE-2026-78059 | SourceCodester Stock Management System 1.0 printOrder.php clientName/clientContact cross site scripting
VulDB·1d ago·cve_linking
C
CVE-2026-78057 | sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5 Management Mutation sql injection
VulDB·1d ago·cve_linking
C
CVE-2026-78056 | sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5 Dashboard roll_no/teacher_name sql injection
VulDB·1d ago·cve_linking
C
CVE-2026-78055 | SourceCodester Class and Exam Timetabling System 1.0 /BSIT2.php course cross site scripting
VulDB·1d ago·cve_linking
C
CVE-2026-78054 | SourceCodester Class and Exam Timetabling System 1.0 /BSIS1.php course cross site scripting
VulDB·1d ago·cve_linking
C
CVE-2026-78003 | Mailgun for Plugin up to 2.2.0 on WordPress add_list addresses server-side request forgery
VulDB·1d ago·cve_linking
Articles are automatically fetched from RSS feeds, pre-filtered for security relevance, and analyzed by LLM for vulnerability extraction. View feed sources