CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “es”

190 vulnerabilities found for “es”

Page 1 of 10

CVE-2025-47371
MEDIUM6.5

Transient DOS when an LTE RLC packet with invalid TB is received by UE.

qualcomm / 5g_fixed_wireless_access_platform_firmware+124
Adjacent
Published Mar 2, 2026
Page 1 of 10
CVE-2026-27734
MEDIUM6.5

Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/containers/logs and GET /api/beszel/containers/info pass the user-supplied "container" query parameter to the agent without validation. The agent constructs Docker Engine API URLs using fmt.Sprintf with the raw value instead of url.PathEscape(). Since Go's http.Client does not sanitize `../` sequences from URL paths sent over unix sockets, an authenticated user (including readonly role) can traverse to arbitrary Docker API endpoints on agent hosts, exposing sensitive infrastructure details. Version 0.18.4 fixes the issue.

beszel / beszel
Network
Published Feb 27, 2026
CVE-2025-9840
MEDIUM6.3

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

angeljudesuarez / sports_management_system
Network
Published Sep 2, 2025
CVE-2025-9767
HIGH7.3

A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /Admin/sporttype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

angeljudesuarez / sports_management_system
Network
Published Sep 1, 2025
CVE-2025-9764
HIGH7.3

A flaw has been found in itsourcecode Sports Management System 1.0. Impacted is an unknown function of the file /Admin/resultdetails.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

angeljudesuarez / sports_management_system
Network
Published Sep 1, 2025
CVE-2025-9766
HIGH7.3

A vulnerability was found in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/facilitator.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

angeljudesuarez / sports_management_system
Network
Published Sep 1, 2025
CVE-2025-9768
MEDIUM6.3

A vulnerability was identified in itsourcecode Sports Management System 1.0. This impacts an unknown function of the file /Admin/mode.php. The manipulation of the argument code leads to sql injection. The attack is possible to be carried out remotely.

angeljudesuarez / sports_management_system
Network
Published Sep 1, 2025
CVE-2025-9765
HIGH7.3

A vulnerability has been found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/tournament_details.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

angeljudesuarez / sports_management_system
Network
Published Sep 1, 2025
CVE-2025-0165
HIGH7.6

IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

ibm / watsonx_orchestrate_cartridge_for_ibm_cloud_pak_for_data+1
Network
Published Aug 30, 2025
CVE-2025-9596
HIGH7.3

A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /login.php. This manipulation of the argument User causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

angeljudesuarez / sports_management_system
Network
Published Aug 29, 2025
CVE-2025-9156
HIGH7.3

A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

angeljudesuarez / sports_management_system
Network
Published Aug 19, 2025
CVE-2025-8925
HIGH7.3

A vulnerability has been found in itsourcecode Sports Management System 1.0. Affected is an unknown function of the file /Admin/match.php. The manipulation of the argument code leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

angeljudesuarez / sports_management_system
Network
Published Aug 13, 2025
CVE-2024-32487
HIGH8.6

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

greenwoodsoftware / less+4
Local
Published Apr 13, 2024
CVE-2023-32250
CRITICAL9.0

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.

linux / linux_kernel+9
Network
Published Jul 10, 2023
CVE-2021-43899
CRITICAL9.8

Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability

microsoft / wireless_display_adapter_firmware
Network
Published Dec 15, 2021
CVE-2020-12464
MEDIUM6.7

usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.

linux / linux_kernel+22
Local
Published Apr 29, 2020
CVE-2018-10197
CRITICAL9.8

There is a time-based blind SQL injection vulnerability in the Access Manager component before 9.18.040 and 10.x before 10.18.040 in ELO ELOenterprise 9 and 10 and ELOprofessional 9 and 10 that makes it possible to read all database content. The vulnerability exists in the ticket HTTP GET parameter. For example, one can succeed in reading the password hash of the administrator user in the "userdata" table from the "eloam" database.

elo / access_manager+1
Network
Published Jul 11, 2018
CVE-2018-8327
CRITICAL9.8

A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.

microsoft / powershell+1
Network
Published Jul 11, 2018
CVE-2018-8306
MEDIUM5.5

A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not properly manage user input, aka "Microsoft Wireless Display Adapter Command Injection Vulnerability." This affects Microsoft Wireless Display Adapter V2 Software.

microsoft / wireless_display_adapter_firmware+2
Adjacent
Published Jul 11, 2018
CVE-2017-7657
CRITICAL9.8

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.

eclipse / jetty+25
Network
Published Jun 26, 2018