6.9

CVSS4.0

CVE-2026-0585 - code-projects Online Product Reservation System GET Parameter order_view.php sql injection

A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the file /order_view.php of the component GET Parameter Handler. Such manipulation of the argument transaction_id leads to sql injection. The attack can be executed …

📅 Published: Jan. 5, 2026, 10:02 a.m. 🔄 Last Modified: April 18, 2026, 8:30 p.m.

5.3

CVSS4.0

CVE-2026-0584 - code-projects Online Product Reservation System left_cart.php sql injection

A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been ma…

📅 Published: Jan. 5, 2026, 9:32 a.m. 🔄 Last Modified: April 18, 2026, 8:30 a.m.

6.9

CVSS4.0

CVE-2026-0583 - code-projects Online Product Reservation System User Login login.php sql injection

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/user/login.php of the component User Login. The manipulation of the argument emailadd results in sql injection. The attack may be launched remotely. Th…

📅 Published: Jan. 5, 2026, 9:02 a.m. 🔄 Last Modified: April 18, 2026, 8:30 a.m.

8.8

CVSS4.0

CVE-2025-66518 - Apache Kyuubi: Unauthorized directory access due to missing path normalization

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade t…

📅 Published: Jan. 5, 2026, 8:46 a.m. 🔄 Last Modified: Jan. 27, 2026, 9:32 p.m.

5.3

CVSS4.0

CVE-2026-0582 - itsourcecode Society Management System edit_activity_query.php sql injection

A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_activity_query.php. The manipulation of the argument Title leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be …

📅 Published: Jan. 5, 2026, 8:32 a.m. 🔄 Last Modified: April 18, 2026, 7:30 p.m.

8.7

CVSS4.0

CVE-2025-15240 - Quanta Computer|QOCA aim AI Medical Cloud Platform - Arbitrary File Upload

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

📅 Published: Jan. 5, 2026, 8:18 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:10 p.m.

7.1

CVSS4.0

CVE-2025-15239 - Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Jan. 5, 2026, 8:10 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:09 p.m.

5.3

CVSS4.0

CVE-2026-0581 - Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection

A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be …

📅 Published: Jan. 5, 2026, 8:02 a.m. 🔄 Last Modified: April 18, 2026, 8:30 a.m.

7.1

CVSS4.0

CVE-2025-15238 - Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Jan. 5, 2026, 8 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:09 p.m.

4.8

CVSS4.0

CVE-2025-15022 - Cross-site scripting in Action caption

Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS) if caption content is derived from user input. In Vaadin Framework 7 and 8, the Action class is a general-purpose class that may be used by multiple components. The fixed versio…

📅 Published: Jan. 5, 2026, 7:52 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2291 of 34,919
« previous page » next page
Filters