Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 9 April 2026
RSS25 vulnerabilities published on 9 April 2026
Severity:
Tenda AC15 Router: Remote Password Change Manipulation Risk
CVE-2026-5830
A weakness in the password change feature of Tenda AC15 routers can be exploited remotely, potentially allowing unauthorized access to the device. This means an attacker can gain control over the rout...
7.4
Vertex Addons for Elementor plugin: Attackers can install unwanted plugins
CVE-2026-4326
The Vertex Addons for Elementor plugin for WordPress is vulnerable to unauthorized plugin installation and activation in all versions up to 1.6.4. If not updated, attackers with a basic level of acces...
8.8
D-Link DIR-645: Remote Attack via Malicious CGI Request
CVE-2026-5815
A security weakness in the D-Link DIR-645 router's CGI interface allows an attacker to potentially exploit it remotely. This affects older versions of the router that are no longer supported by the ma...
7.4
Atototo API Lab MCP Exposes Server-Side Request Forgery
CVE-2026-5832
A weakness in Atototo API Lab MCP version 0.2.1 and earlier allows hackers to trick the server into making unauthorized requests. This could be exploited remotely and malicious code has been made avai...
6.9
Simple IT Discussion Forum 1.0: SQL Injection Risk in post_id Input
CVE-2026-5829
The Simple IT Discussion Forum software has a security flaw in its posting system. If an attacker manipulates the post_id field, they may be able to access sensitive data. We recommend updating to a p...
6.9
Simple IT Discussion Forum: SQL Injection in Comment Addition
CVE-2026-5828
A security flaw in the Simple IT Discussion Forum software allows an attacker to inject malicious SQL code when adding comments. This could allow an attacker to access sensitive data or take control o...
6.9
Simple IT Discussion Forum 1.0: SQL Injection Risk
CVE-2026-5827
A security flaw in the Simple IT Discussion Forum 1.0 software allows an attacker to inject malicious code into the database, potentially stealing or modifying sensitive data. This can happen if an at...
6.9
Simple Laundry System 1.0: User ID Input Can Be Abused
CVE-2026-5824
A security flaw in Simple Laundry System 1.0 allows an attacker to manipulate user input, potentially gaining unauthorized access to the system. This could happen if an attacker sends malicious data t...
6.9
PHPGurukul Online Course Registration 3.1 allows remote SQL injection attacks
CVE-2026-5814
The PHPGurukul Online Course Registration 3.1 system has a security flaw that lets attackers access sensitive data by manipulating certain inputs. This can be done from anywhere on the internet, and a...
6.9
Agions Taskflow-AI: Unsecured Commands Can Be Injected Remotely
CVE-2026-5831
A security flaw in Agions Taskflow-AI versions up to 2.1.8 allows an attacker to inject malicious commands into the system, potentially leading to unauthorized actions. This affects users who have thi...
5.3
itsourcecode Construction Management System: Remote SQL Injection in borrowed_tool_report.php
CVE-2026-5823
A security flaw in the itsourcecode Construction Management System allows an attacker to remotely inject malicious code into the system. This could happen if someone enters malicious input when access...
5.3
Simple IT Discussion Forum 1.0 allows code injection through category edit
CVE-2026-5826
A security issue in Simple IT Discussion Forum 1.0 can allow an attacker to inject malicious code into the forum. This could happen if a user is tricked into visiting a malicious link, which could pot...
5.3
Simple Laundry System 1.0: User ID Tampering Risk
CVE-2026-5825
The Simple Laundry System 1.0 has a security weakness in its user ID handling, allowing an attacker to potentially inject malicious code. This could happen if a user with malicious intent sends specia...
5.3
Adobe Acrobat DC: Unpatched exploit allows remote code execution
CGA-pjgc-2h7p-246m
Adobe Acrobat DC is vulnerable to an unpatched security issue that allows attackers to execute malicious code on a remote computer. This could lead to unauthorized access to sensitive data or system c...
MINI-8786-9qqj-wp4h
MINI-8786-9qqj-wp4h
MINI-9ph3-4mg7-mhpf
MINI-9ph3-4mg7-mhpf
MINI-35g4-4h68-x8fr
MINI-35g4-4h68-x8fr
CGA-hj9h-9239-q2wg
CGA-hj9h-9239-q2wg
CGA-hj9h-9239-q2wg
Adobe Acrobat Reader allows arbitrary code execution via crafted PDF
CGA-hg64-9r55-fh6m
Adobe Acrobat Reader has a security flaw that could allow hackers to execute malicious code on your computer if you open a specially crafted PDF file. This could allow them to access sensitive informa...
CGA-33f9-cxc3-pfp4
CGA-33f9-cxc3-pfp4
CGA-5638-w48x-xg3x
CGA-5638-w48x-xg3x
WordPress Plugin 'WP User Manager' Allows Unauthenticated Access
CGA-f5qq-7g8r-h66w
An issue with the WP User Manager plugin for WordPress allows unauthorized users to gain access to administrator accounts. This could allow attackers to take control of the website. Update the plugin ...
CGA-6rr8-4mqx-6m62
CGA-6rr8-4mqx-6m62
CGA-5mwp-vqrf-gmgh
CGA-5mwp-vqrf-gmgh