2.7

CVSS3.1

CVE-2026-37589 -

SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:25 p.m.

8.5

CVSS3.1

CVE-2026-38527 - Server-Side Request Forgery in Webkul Krayin CRM Webhooks Endpoint Enables Internal Network Discove…

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

9.9

CVSS3.1

CVE-2026-38526 - Authenticated Arbitrary File Upload Allowing Remote Code Execution in Webkul Krayin CRM v2.2.x

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

2.7

CVSS3.1

CVE-2026-37600 -

SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:32 p.m.

4.6

CVSS3.1

CVE-2025-69893 - Side-Channel Vulnerability in BIP-39 Mnemonic Processing on Trezor Wallets Enables Mnemonic Exposure

A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which induce non-constant tim…

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

2.7

CVSS3.1

CVE-2026-37593 -

SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:32 p.m.

9.8

CVSS3.1

CVE-2025-63939 - SQL Injection in Grocery Store Management System via search_products_itname.php

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.

9.8

CVSS3.1

CVE-2025-70023 -

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

9.8

CVSS3.1

CVE-2025-61260 - OpenAI Codex CLI Command Injection via Malicious Configuration Files

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads pr…

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:24 p.m.

9.8

CVSS3.1

CVE-2025-65135 - Time-Based Blind SQL Injection in Student Management System Admin Endpoint

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.
Total resulsts: 346890
Page 263 of 34,689
Β« previous page Β» next page
Filters