9.8

CVSS3.1

CVE-2025-63939 - SQL Injection in Grocery Store Management System via search_products_itname.php

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

9.8

CVSS3.1

CVE-2025-70023 -

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

9.8

CVSS3.1

CVE-2025-61260 - OpenAI Codex CLI Command Injection via Malicious Configuration Files

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads pr…

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:24 p.m.

9.8

CVSS3.1

CVE-2025-65135 - Time-Based Blind SQL Injection in Student Management System Admin Endpoint

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2026-30480 - Authenticated LFI in LibreNMS NFSen Module Exposes Arbitrary PHP Files

A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

2.7

CVSS3.1

CVE-2026-37591 -

Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:32 p.m.

0.0

CVE-2025-65134 - Reflected XSS via Email Parameter in School Management System 1.0

In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the email POST parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2026-38533 -

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 9 a.m.

2.7

CVSS3.1

CVE-2026-37602 -

SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:32 p.m.

6.1

CVSS3.1

CVE-2025-65136 - Reflected Cross‑Site Scripting in School Management System Contact Page

In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.
Total resulsts: 346172
Page 192 of 34,618
Β« previous page Β» next page
Filters