6.9

CVSS4.0

CVE-2026-0579 - code-projects Online Product Reservation System POST Parameter edit.php sql injection

A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the file /handgunner-administrator/edit.php of the component POST Parameter Handler. The manipulation of the argument prod_id/name/price/model/serial results in sql injection. The attac…

πŸ“… Published: Jan. 4, 2026, 12:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:12 a.m.

6.9

CVSS4.0

CVE-2026-0578 - code-projects Online Product Reservation System delete.php sql injection

A vulnerability has been found in code-projects Online Product Reservation System 1.0. Affected by this issue is some unknown functionality of the file /handgunner-administrator/delete.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit…

πŸ“… Published: Jan. 4, 2026, 12:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:12 a.m.

5.1

CVSS4.0

CVE-2025-15443 - CRMEB product_export sql injection

A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/product/product_export. Such manipulation of the argument cate_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. T…

πŸ“… Published: Jan. 4, 2026, 11:32 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:12 a.m.

5.1

CVSS4.0

CVE-2025-15442 - CRMEB product_list sql injection

A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/export/product_list. This manipulation of the argument cate_id causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. …

πŸ“… Published: Jan. 4, 2026, 11:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:12 a.m.

5.3

CVSS4.0

CVE-2026-0577 - code-projects Online Product Reservation System prod.php unrestricted upload

A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /handgunner-administrator/prod.php. Executing a manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploi…

πŸ“… Published: Jan. 4, 2026, 9:32 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

4.9

CVSS3.1

CVE-2025-14830 - JFrog Artifactory Cross-Site Scripting

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.

πŸ“… Published: Jan. 4, 2026, 9:17 a.m. πŸ”„ Last Modified: Jan. 27, 2026, 8:38 p.m.

6.9

CVSS4.0

CVE-2026-0576 - code-projects Online Product Reservation System Parameter prod.php sql injection

A vulnerability was detected in code-projects Online Product Reservation System 1.0. Affected is an unknown function of the file /handgunner-administrator/prod.php of the component Parameter Handler. Performing a manipulation of the argument cat/price/name/model/serial results in sql injection. It …

πŸ“… Published: Jan. 4, 2026, 9:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

6.9

CVSS4.0

CVE-2026-0575 - code-projects Online Product Reservation System Administrator Login adminlogin.php sql injection

A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unknown function of the file /handgunner-administrator/adminlogin.php of the component Administrator Login. Such manipulation of the argument emailadd/pass leads to sql injection. The …

πŸ“… Published: Jan. 4, 2026, 6:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:11 a.m.

5.3

CVSS4.0

CVE-2026-0574 - yeqifu warehouse Request UserController.java saveUserRole improper authorization

A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java of the component Request Handler. This manipulation causes improper authorizati…

πŸ“… Published: Jan. 4, 2026, 2:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:11 a.m.

6.9

CVSS4.0

CVE-2025-3660 - Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retriev…

πŸ“… Published: Jan. 3, 2026, 11:33 p.m. πŸ”„ Last Modified: Feb. 3, 2026, 5:32 p.m.
Total resulsts: 344055
Page 1787 of 34,406
Β« previous page Β» next page
Filters