2.7

CVSS3.1

CVE-2026-37601 - SQL Injection in Patient Appointment Scheduler System v1.0

SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:31 p.m.

2.7

CVSS3.1

CVE-2026-37592 - SQL Injection in Storage Unit Rental Management System's Pricing Management Endpoint

Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:31 p.m.

2.7

CVSS3.1

CVE-2026-37590 - SQL Injection in Storage Unit Rental Management System Admin Rent Page

SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:31 p.m.

2.7

CVSS3.1

CVE-2026-37589 - SQL Injection in Storage Unit Rental Management System

SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:31 p.m.

0.0

CVE-2025-69893 - Side‑Channel Attack Enables Recovery of BIP‑39 Mnemonic on Trezor Wallets

A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which induce non-constant tim…

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:37 p.m.

2.7

CVSS3.1

CVE-2026-37596 - SQL Injection in SourceCodester Online Employees Work From Home Attendance System 1.0

SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:31 p.m.

0.0

CVE-2026-38533 - Improper Authorization Enables Modification of Authentication Fields in Snipe‑IT

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:31 p.m.

0.0

CVE-2025-65134 -

In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the email POST parameter.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 6:03 p.m.

9.9

CVSS3.1

CVE-2026-38526 - Authenticated Arbitrary File Upload Allowing Remote Code Execution in Webkul Krayin CRM v2.2.x

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 6:17 p.m.

2.7

CVSS3.1

CVE-2026-37595 - SQL Injection in SourceCodester Online Employees Work From Home Attendance System

SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:31 p.m.
Total resulsts: 344716
Page 49 of 34,472
Β« previous page Β» next page
Filters