Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-13562

Edimax EW-7478APC POST Request formiNICSiteSurvey buffer overflow_CVE-2026-13562

A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the compone...

Edimax EW-7478APC 1.04 CVE
MEDIUM 5.3 CVE-2026-13561

Edimax EW-7478APC POST Request formiNICbasic os command injection_CVE-2026-13561

A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the...

Edimax EW-7478APC 1.04 CVE
MEDIUM 5.3 CVE-2026-13560

Edimax EW-7478APC POST Request formAccept os command injection_CVE-2026-13560

A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccep...

Edimax EW-7478APC 1.04 CVE
MEDIUM 6.9 CVE-2026-13559

code-projects Real State Services single-list_sale.php add sql injection_CVE-2026-13559

A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=a...

code-projects Real State Services 1.0 CVE
MEDIUM 5.1 CVE-2026-13558

CodeAstro Complaint Management System Report addreport cross site scripting_CVE-2026-13558

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/ad...

CodeAstro Complaint Management System 1.0 CVE
HIGH 7.1 CVE-2026-57346

WordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerability_CVE-2026-57346

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This ...

Epiphyt Embed Privacy n/a CVE
HIGH 8.8 CVE-2026-25707

Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp_CVE-2026-25707

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying re...

SUSE libzypp CVE
HIGH 7.1 CVE-2026-13601

Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications_CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak applica...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 5.3 CVE-2026-13557

itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting_CVE-2026-13557

A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_r...

itsourcecode Online Hotel Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-13556

itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting_CVE-2026-13556

A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/contro...

itsourcecode Online Hotel Management System 1.0 CVE