Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 5 April 2026
RSS87 vulnerabilities published on 5 April 2026
Severity:
Tenda AC10 Routers Can Be Crashed by Malicious Password Changes
CVE-2026-5550
A bug in the Tenda AC10's password change feature on certain routers can be exploited remotely, potentially causing the device to crash. This affects multiple devices. To fix this, update to a newer v...
8.7
Tenda AC10 Router Allows Remote Password Change Manipulation
CVE-2026-5548
A security issue in the Tenda AC10 router's password change feature allows an attacker to potentially hijack the device. The issue affects the password change process, which can be exploited remotely....
8.7
UTT HiPER 1250GW: Remote Code Execution Possible Through Malicious Input
CVE-2026-5544
A security issue in UTT HiPER 1250GW firmware (up to version 3.2.7) could allow an attacker to execute malicious code remotely. This means an attacker could potentially take control of the device with...
7.4
Provectus Kafka-UI: Remote Code Execution via Unauthenticated Access
CVE-2026-5562
A security flaw in Provectus Kafka-UI versions up to 0.7.2 allows an attacker to run malicious code on the system without needing a username or password. This could lead to unauthorized access and dat...
6.9
Concert Ticket Reservation System 1.0 login.php SQL Injection
CVE-2026-5555
The Concert Ticket Reservation System 1.0 has a security weakness in its login feature. If an attacker knows how to manipulate the login email field, they could potentially access sensitive data or ta...
6.9
Concert Ticket Reservation System 1.0: Remote SQL Injection Risk
CVE-2026-5554
A vulnerability in the Concert Ticket Reservation System 1.0 allows attackers to inject malicious code into the system, potentially allowing them to access sensitive information or disrupt the system....
6.9
itsourcecode Free Hotel Reservation System login page vulnerable to email hacking
CVE-2026-5551
The login page of itsourcecode Free Hotel Reservation System 1.0 may be vulnerable to hacking attempts. This could allow an attacker to access sensitive information. Update the software to the latest ...
6.9
Simple Laundry System 1.0: Remote SQL Injection via Manipulated User Input
CVE-2026-5540
A weakness in Simple Laundry System 1.0 allows attackers to manipulate user data, potentially accessing sensitive information. This could happen if an attacker sends malicious input to the system. To ...
6.9
FedML-AI FedML gRPC Server Allows Remote Code Execution
CVE-2026-5536
FedML-AI FedML versions 0.8.9 and below have a security risk where a remote attacker could potentially execute malicious code on the server. This is a serious issue because it could allow an attacker ...
6.9
itsourcecode Online Enrollment System: SQL Injection Risk Through Malicious User ID
CVE-2026-5534
The itsourcecode Online Enrollment System has a security flaw that allows an attacker to manipulate user data through a maliciously crafted user ID. This could lead to unauthorized access to sensitive...
6.9
Apache HTTP Server can crash when handling SYN packets
CVE-2026-5590
The Apache HTTP Server may crash if it receives a SYN packet while processing a connection teardown. This can happen when the server is under heavy traffic. To fix this issue, update to the latest ver...
6.4
Campcodes Complete POS Management and Inventory System: Environment Variable Injection
CVE-2026-5561
The Campcodes Complete POS Management and Inventory System is vulnerable to an environment variable injection attack. This means that an attacker could potentially inject malicious data into the syste...
5.3
PHPGurukul Online Shopping Portal: SQL Injection in Payment Processing
CVE-2026-5560
An attacker can inject malicious SQL code into the payment processing system of PHPGurukul Online Shopping Portal, potentially allowing them to access sensitive data or take control of the system. Thi...
5.3
PyBlade Template Engine Allows Remote Hackers to Inject Malicious Code
CVE-2026-5559
A security issue has been found in the template engine of PyBlade, a Python library used for creating web pages. If exploited, hackers could inject malicious code into web pages, potentially leading t...
5.3
PHPGurukul Online Shopping Portal vulnerable to SQL injection
CVE-2026-5558
The PHPGurukul Online Shopping Portal's pending-orders feature has a security flaw that can allow an attacker to manipulate data using SQL injection. This means an attacker could potentially access se...
5.3
Pi-Mono Slack Bot Authentication Bypass Exposed
CVE-2026-5557
A security issue in Pi-Mono Slack Bot up to version 0.58.4 could allow an attacker to bypass authentication and access the bot remotely. This could potentially lead to unauthorized access to sensitive...
5.3
Badlogic pi-mono allows remote code injection
CVE-2026-5556
A bug in pi-mono versions up to 0.58.4 allows attackers to inject malicious code. This means that if you're using an outdated version, an attacker could potentially take control of your system. Update...
5.3
itsourcecode Online Cellphone System 1.0: Unsecured Data Exposure via Remote SQL Injection
CVE-2026-5553
The itsourcecode Online Cellphone System 1.0 has a weakness in its Parameter Handler component. This flaw allows an attacker to inject malicious code and potentially access sensitive data. To protect ...
5.3
PHPGurukul Online Shopping Portal Project 2.1: SQL Injection in sub-category.php
CVE-2026-5552
The PHPGurukul Online Shopping Portal Project 2.1 has a security weakness in its sub-category.php file. This could allow an attacker to access sensitive information in the database. We recommend updat...
5.3
Tenda AC10 Router Allows Remote Code Execution
CVE-2026-5547
A bug in the Tenda AC10 router's configuration tool lets hackers take control of the device. This means they can run any command they want on the router, which could lead to serious security issues. T...
5.3
Campcodes Complete Online Learning Management System allows unauthorized file upload
CVE-2026-5546
A weakness in Campcodes Complete Online Learning Management System 1.0 allows attackers to upload any file without restriction, potentially leading to malicious content being shared on the system. Thi...
5.3
PHPGurukul User Management System: SQL Injection in User Registration
CVE-2026-5543
A bug in the User Registration & Login and User Management System for PHPGurukul allows hackers to potentially access or manipulate sensitive user data. This could happen if an attacker knows the corr...
5.3
QingdaoU OnlineJudge Version 1.6.1 Allows Remote Server Forgery
CVE-2026-5538
If you're using QingdaoU OnlineJudge version 1.6.1, an attacker could potentially trick the system into making unauthorized requests to other servers. This could be a security risk if your users' sens...
5.3
halex CourseSEL Unsecured Data Input in GET Requests
CVE-2026-5537
A security flaw in halex CourseSEL allows attackers to inject malicious SQL code when using a specific parameter in a GET request. This could potentially allow unauthorized access to sensitive data. U...
5.3
ScrapeGraphAI: Malicious Code Injection in GenerateCodeNode
CVE-2026-5532
An attacker can inject malicious code into ScrapeGraphAI's GenerateCodeNode, potentially allowing them to execute arbitrary system commands. This issue affects versions 1.74.0 and earlier. We recommen...
5.3