6.5

CVSS3.1

CVE-2025-13679 - Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exp…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_order_by_id() function in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber…

πŸ“… Published: Jan. 8, 2026, 7:04 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 1:25 p.m.

6.9

CVSS4.0

CVE-2026-0700 - code-projects Intern Membership Management System check_admin.php sql injection

A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been …

πŸ“… Published: Jan. 8, 2026, 7:02 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:19 p.m.

0.0

CVE-2026-22635 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22634 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22636 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22631 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22633 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22632 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22630 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

5.1

CVSS4.0

CVE-2026-0699 - code-projects Intern Membership Management System edit_activity.php sql injection

A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. Remote exploitation of the attack is possible. The exploi…

πŸ“… Published: Jan. 8, 2026, 6:32 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:21 p.m.
Total resulsts: 327160
Page 52 of 32,716
Β« previous page Β» next page
Filters