9.8

CVSS3.1

CVE-2025-63939 -

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 3:02 p.m.

7.1

CVSS3.1

CVE-2026-38528 -

Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 3:14 p.m.

0.0

CVE-2025-65136 -

In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 3:08 p.m.

0.0

CVE-2026-37602 -

SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 2:09 p.m.

0.0

CVE-2026-37593 -

SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 1:59 p.m.

0.0

CVE-2026-31049 -

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 1:28 p.m.

9.8

CVSS3.1

CVE-2025-65135 -

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 3:07 p.m.

8.5

CVSS3.1

CVE-2026-38527 -

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 3:13 p.m.

0.0

CVE-2026-37596 -

SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 2:06 p.m.

0.0

CVE-2025-65133 -

A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information.

๐Ÿ“… Published: April 14, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 3:05 p.m.
Total resulsts: 344669
Page 46 of 34,467
ยซ previous page ยป next page
Filters