9.8

CVSS3.1

CVE-2026-30530 - SQL Injection in Online Food Ordering System Allowing Unauthorized Database Access

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious SQL comman…

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:57 p.m.

7.5

CVSS3.1

CVE-2026-29871 -

A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong AI News and Podcast Agent backend in FastAPI backend, stream-audio endpoint, in file routers/podcast_router.py, in function stream_audio. The stream-a…

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:38 a.m.

6.1

CVSS3.1

CVE-2025-61190 -

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover filtering functionality. The vulnerability exists due to improper sanitization of user-supplied input via the filter_type_1 parameter.

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 7:55 a.m.

7.5

CVSS3.1

CVE-2026-30575 - Negative Quantity Stock Entry Exploit in Pharmacy Management System

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtqty" parameter during stock entry, allowing negative values to be processed. This causes the system to decrease the inventory level ins…

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: March 31, 2026, 8:11 p.m.

6.1

CVSS3.1

CVE-2026-30571 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_category.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

7.5

CVSS3.1

CVE-2026-30689 -

A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security.

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:38 a.m.

8.3

CVSS3.1

CVE-2026-30534 - SQL Injection in Admin Category Management of Online Food Ordering System

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:57 p.m.

8.8

CVSS3.1

CVE-2026-30529 - SQL Injection in SourceCodester Online Food Ordering System v1.0

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker to inject malicious …

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:57 p.m.

9.8

CVSS3.1

CVE-2026-30303 - OS Command Injection in MatterAI Axon Code Auto‑Approval Module Enables Remote Code Execution

The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the Wind…

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:38 a.m.

6.5

CVSS3.1

CVE-2025-69988 -

BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proximity can associate with this open network. Once connected, the attacker gains access to the camera's private network interface and can retrieve sensitive information, including th…

πŸ“… Published: March 27, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.
Total resulsts: 349182
Page 841 of 34,919
Β« previous page Β» next page
Filters