8.2

CVSS3.1

CVE-2023-36331 -

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId.

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:09 p.m.

5.4

CVSS3.1

CVE-2021-41074 -

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 6:45 p.m.

9.1

CVSS3.1

CVE-2025-51567 -

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 5:31 p.m.

9.8

CVSS3.1

CVE-2025-65552 -

D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attacker within RF range to record valid alarm/control frames and …

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Feb. 3, 2026, 7:39 p.m.

9.4

CVSS3.1

CVE-2025-67146 -

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.php, and (3) gym_search.php, and via the 'id' parameter in (4) payment_search.php. An unauthenticated remote attacker can exploit these issu…

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 27, 2026, 8:22 p.m.

9.8

CVSS3.1

CVE-2025-67147 -

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and 'login_key' parameters in (…

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-46067 -

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 10:03 p.m.

6.9

CVSS4.0

CVE-2026-0851 - code-projects Online Music Site AdminAddUser.php sql injection

A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publ…

πŸ“… Published: Jan. 11, 2026, 11:32 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

5.1

CVSS4.0

CVE-2026-0850 - code-projects Intern Membership Management System delete_activity.php sql injection

A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. The attack may be launched remotely. The exploit has been …

πŸ“… Published: Jan. 11, 2026, 11:02 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

8.1

CVSS3.1

CVE-2025-68493 - Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

πŸ“… Published: Jan. 11, 2026, 1:05 p.m. πŸ”„ Last Modified: March 11, 2026, 4:16 p.m.
Total resulsts: 347061
Page 1986 of 34,707
Β« previous page Β» next page
Filters