5.3

CVSS4.0

CVE-2026-3785 - EasyCMS Request Parameter RbacnodeAction.class.php sql injection

A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order leads to sql injection. The attack can be initiated remotely. The exploit is pub…

πŸ“… Published: March 8, 2026, 10:32 p.m. πŸ”„ Last Modified: April 16, 2026, 4:15 a.m.

5.3

CVSS4.0

CVE-2026-3771 - SourceCodester/janobe Resort Reservation System accomodation.php sql injection

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the pu…

πŸ“… Published: March 8, 2026, 9:32 p.m. πŸ”„ Last Modified: April 16, 2026, 10:30 a.m.

5.3

CVSS4.0

CVE-2026-3770 - SourceCodester Computer Laboratory Management System cross-site request forgery

A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.

πŸ“… Published: March 8, 2026, 9:02 p.m. πŸ”„ Last Modified: April 16, 2026, 10:30 a.m.

8.7

CVSS4.0

CVE-2026-3769 - Tenda F453 WrlclientSet stack-based overflow

A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function WrlclientSet of the file /goform/WrlclientSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

πŸ“… Published: March 8, 2026, 9:02 p.m. πŸ”„ Last Modified: April 16, 2026, 10:30 a.m.

8.7

CVSS4.0

CVE-2026-3768 - Tenda F453 WrlExtraSet formWrlExtraSet stack-based overflow

A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has …

πŸ“… Published: March 8, 2026, 8:32 p.m. πŸ”„ Last Modified: April 16, 2026, 4:15 a.m.

5.3

CVSS4.0

CVE-2026-3767 - itsourcecode sanitize or validate this input teacher-attendance.php sql injection

A weakness has been identified in itsourcecode sanitize or validate this input 1.0. Affected is an unknown function of the file /admin/teacher-attendance.php. Executing a manipulation of the argument teacher_id can lead to sql injection. The attack may be launched remotely. The exploit has been mad…

πŸ“… Published: March 8, 2026, 8:32 p.m. πŸ”„ Last Modified: April 17, 2026, noon

5.1

CVSS4.0

CVE-2026-3766 - SourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site scripting

A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the argument fullname results in cross site scripting. The attack may be initiated remotely. The exploi…

πŸ“… Published: March 8, 2026, 8:02 p.m. πŸ”„ Last Modified: April 16, 2026, 4:15 a.m.

6.9

CVSS4.0

CVE-2026-3765 - itsourcecode University Management System att_single_view.php sql injection

A vulnerability was identified in itsourcecode University Management System 1.0. This affects an unknown function of the file /att_single_view.php. Such manipulation of the argument dt leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

πŸ“… Published: March 8, 2026, 8:02 p.m. πŸ”„ Last Modified: April 16, 2026, 4:15 a.m.

6.9

CVSS4.0

CVE-2026-3764 - SourceCodester Client Database Management System superadmin_user_update.php improper authorization

A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /superadmin_user_update.php. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed…

πŸ“… Published: March 8, 2026, 7:32 p.m. πŸ”„ Last Modified: April 17, 2026, noon

5.3

CVSS4.0

CVE-2026-3763 - code-projects Simple Flight Ticket Booking System showhistory.php cross site scripting

A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown function of the file showhistory.php. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be …

πŸ“… Published: March 8, 2026, 7:02 p.m. πŸ”„ Last Modified: April 16, 2026, 10:30 a.m.
Total resulsts: 349182
Page 1250 of 34,919
Β« previous page Β» next page
Filters