CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
93,750 results Clear all
CVE-2026-30896 7.8 HIGH EPSS 0.00
Qsee Client <=1.0.1 - DLL Hijacking
The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some malicious DLL to the same directory and execute the affected installer, then arbitrary code may be executed with the administrative privilege.
CWE-427 Mar 09, 2026
CVE-2026-3802 8.8 HIGH 1 Writeup EPSS 0.00
Tenda i3 1.0.0.6(2204) - Buffer Overflow
A vulnerability was determined in Tenda i3 1.0.0.6(2204). Affected by this issue is the function formexeCommand of the file /goform/exeCommand. Executing a manipulation of the argument cmdinput can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
CWE-119 Mar 09, 2026
CVE-2026-3801 8.8 HIGH 1 Writeup EPSS 0.00
Tenda i3 1.0.0.6(2204) - Buffer Overflow
A vulnerability was found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formSetAutoPing of the file /goform/setAutoPing. Performing a manipulation of the argument ping1/ping2 results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
CWE-119 Mar 09, 2026
CVE-2026-3799 8.8 HIGH 1 Writeup EPSS 0.00
Tenda i3 1.0.0.6(2204) - Buffer Overflow
A flaw has been found in Tenda i3 1.0.0.6(2204). This impacts the function formSetCfm of the file /goform/setcfm. This manipulation of the argument funcpara1 causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CWE-119 Mar 09, 2026
CVE-2026-3631 7.5 HIGH EPSS 0.00
Delta Electronics COMMGR2 - DoS
Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.
CWE-125 Mar 09, 2026
CVE-2026-3794 7.3 HIGH EPSS 0.00
doramart DoraCMS 3.0.x - Auth Bypass
A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-287 Mar 09, 2026
CVE-2026-3787 7.0 HIGH EPSS 0.00
UltraVNC 1.6.4.0 - Path Traversal
A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase.dll of the component Windows Service. This manipulation causes uncontrolled search path. The attack requires local access. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-426 Mar 08, 2026
CVE-2026-3769 8.8 HIGH 1 Writeup EPSS 0.00
Tenda F453 1.0.0.3 - Buffer Overflow
A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function WrlclientSet of the file /goform/WrlclientSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
CWE-119 Mar 08, 2026
CVE-2026-3768 8.8 HIGH 1 Writeup EPSS 0.00
Tenda F453 1.0.0.3 - Buffer Overflow
A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
CWE-119 Mar 08, 2026
CVE-2026-3765 7.3 HIGH EPSS 0.00
itsourcecode University Management System 1.0 - SQL Injection
A vulnerability was identified in itsourcecode University Management System 1.0. This affects an unknown function of the file /att_single_view.php. Such manipulation of the argument dt leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
CWE-89 Mar 08, 2026
CVE-2026-3764 7.3 HIGH EPSS 0.00
SourceCodester Client DBMS 1.0 - Auth Bypass
A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /superadmin_user_update.php. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CWE-266 Mar 08, 2026
CVE-2026-3762 7.3 HIGH EPSS 0.00
SourceCodester CDMS 1.0/3.1 - Auth Bypass
A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The manipulation of the argument manager_id leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-266 Mar 08, 2026
CVE-2026-3760 7.3 HIGH EPSS 0.00
itsourcecode University Management System 1.0 - SQL Injection
A vulnerability was detected in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /view_result.php. Performing a manipulation of the argument seme results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CWE-89 Mar 08, 2026
CVE-2026-3759 7.3 HIGH EPSS 0.00
Online Art Gallery Shop 1.0 - SQL Injection
A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CWE-89 Mar 08, 2026
CVE-2026-3758 7.3 HIGH EPSS 0.00
Online Art Gallery Shop 1.0 - SQL Injection
A weakness has been identified in projectworlds Online Art Gallery Shop 1.0. Affected by this issue is some unknown functionality of the file /admin/adminHome.php. This manipulation of the argument Info causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
CWE-89 Mar 08, 2026
CVE-2026-3757 7.3 HIGH EPSS 0.00
Online Art Gallery Shop 1.0 - SQL Injection
A security flaw has been discovered in projectworlds Online Art Gallery Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /?pass=1. The manipulation of the argument fnm results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
CWE-89 Mar 08, 2026
CVE-2026-3747 7.3 HIGH EPSS 0.00
itsourcecode University Management System 1.0 - SQL Injection
A vulnerability was identified in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /add_result.php. Such manipulation of the argument subject leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
CWE-89 Mar 08, 2026
CVE-2026-3746 7.3 HIGH 1 Writeup EPSS 0.00
SourceCodester Tourism Website 1.0 - SQL Injection
A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CWE-89 Mar 08, 2026
CVE-2026-3744 7.3 HIGH 1 Writeup EPSS 0.00
Student Web Portal 1.0 - SQL Injection
A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-74 Mar 08, 2026
CVE-2026-3740 7.3 HIGH EPSS 0.00
itsourcecode University Management System 1.0 - SQL Injection
A weakness has been identified in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_search_student.php. This manipulation of the argument admin_search_student causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
CWE-89 Mar 08, 2026