Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-13534

CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization_CVE-2026-13534

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemorySer...

CherryHQ cherry-studio 1.9.0 CVE
MEDIUM 6.9 CVE-2026-13533

agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access_CVE-2026-13533

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file ...

agentejo Cockpit CMS 0.12.0 CVE
MEDIUM 5.3 CVE-2026-13532

itsourcecode Hospital Management System departmentDoctor.php sql injection_CVE-2026-13532

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the fi...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-13531

itsourcecode Hospital Management System department.php sql injection_CVE-2026-13531

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /department.php. Th...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-13530

itsourcecode Hospital Management System Appointment appointmentdetail.php sql injection_CVE-2026-13530

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /appointmentdetail.php ...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 6.3 CVE-2026-13529

YzmCMS index.php sql injection_CVE-2026-13529

A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipu...

n/a YzmCMS 7.0 CVE
MEDIUM 6.9 CVE-2026-13528

YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal_CVE-2026-13528

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPat...

YunaiV ruoyi-vue-pro 2026.04-jdk8-SNAPSHOT CVE
MEDIUM 6.9 CVE-2026-13527

SourceCodester Class and Exam Timetabling System preview4.php sql injection_CVE-2026-13527

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /pr...

SourceCodester Class and Exam Timetabling System 1.0 CVE
HIGH 8.7 CVE-2026-13516

Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow_CVE-2026-13516

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSe...

Tenda JD12L 16.03.53.23 CVE
HIGH 8.7 CVE-2026-13518

Tenda JD12L addressNat fromAddressNat stack-based overflow_CVE-2026-13518

A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulatio...

Tenda JD12L 16.03.53.23 CVE