2.7
CVE-2026-37592 -
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php.
2.7
CVE-2026-37589 -
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.
8.5
CVE-2026-38527 - Server-Side Request Forgery in Webkul Krayin CRM Webhooks Endpoint Enables Internal Network Discoveβ¦
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.
9.8
CVE-2025-70023 -
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
8.1
CVE-2026-38530 - Broken ObjectβLevel Authorization in Webkul Krayin CRM Exposes Lead Data
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request.
6.1
CVE-2025-69993 - Leaflet: Leaflet: Cross-Site Scripting (XSS) via unsanitized input in bindPopup() method
Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x oneβ¦
2.7
CVE-2026-37600 -
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.
2.7
CVE-2026-37593 -
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.
9.8
CVE-2025-63939 - SQL Injection in Grocery Store Management System via search_products_itname.php
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.
9.8
CVE-2025-65135 - Time-Based Blind SQL Injection in Student Management System Admin Endpoint
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.