2.7
CVE-2026-36941 - SQL Injection Vulnerability in Sourcecodester Online Resort Management System
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php.
9.8
CVE-2026-31283 - Unrestricted Password Reset Causing Email Bombing in Totara LMS
In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack. NOTE: the Supplier's position is that the pwresettime configuration defaults to 30 minutes, the pwresettime configuration is a hardβ¦
2.7
CVE-2026-36873 - SQL Injection in Basic Library System v1.0 /librarysystem/load_admin.php
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php.
6.1
CVE-2026-26460 - HTML Injection Vulnerability in Vtiger CRM Dashboard Module
A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to inject arbitrary HTML content into the dashboard interβ¦
7.5
CVE-2025-69624 - Null Pointer Dereference in Nitro PDF Pro JavaScript Leading to Crash
Nitro PDF Pro for Windows 14.41.1.4 contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true) when app.activeDocs isβ¦
5.5
CVE-2026-6844 - Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory β¦
2.7
CVE-2026-36945 - SQL Injection via manage_client.php in Sourcecodester Repair Shop Management System v1.0
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/clients/manage_client.php
2.7
CVE-2026-36947 -
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/admin/services/view_service.php.
2.7
CVE-2026-36938 - SQL Injection Vulnerability in Sourcecodester Online Resort Management System
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php.
8.8
CVE-2025-51414 - Unrestricted File Upload in Phpgurukul Online Course Registration
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page.