Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-3746 — SourceCodester Simple Responsive Tourism Website Login Login.php sql injection

A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of th…

simple_responsive_tourism_website | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3745 — code-projects Student Web Portal profile.php sql injection

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack …

student_web_portal | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3744 — code-projects Student Web Portal signup.php valreg_passwdation sql injection

A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql i…

student_web_portal | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3743 — YiFang CMS D_singlePageGroup.php update cross site scripting

A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation of the argument Name can lead to cross site script…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3742 — YiFang CMS D_singlePage.php update cross site scripting

A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument Title results in cro…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3741 — YiFang CMS D_friendLink.php update cross site scripting

A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3740 — itsourcecode University Management System admin_search_student.php sql injection

A weakness has been identified in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_search_student.php. This manipulation of the argument admin_search_…

university_management_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3739 — suitenumerique messages ThreadAccess serializers.py ThreadAccessSerializer improper authe…

A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/core/api/serializers.py of the component ThreadAcc…

Remote | Authentication
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3738 — SourceCodester Pet Grooming Management Software Financial Report improper authorization

A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Financial Report Page. The manipulation leads to improp…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3737 — SourceCodester Pet Grooming Management Software User Creation add_user.php improper autho…

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipu…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3736 — code-projects Simple Flight Ticket Booking System SearchResultRoundtrip.php sql injection

A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulati…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3735 — code-projects Simple Flight Ticket Booking System SearchResultOneway.php sql injection

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulati…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3734 — SourceCodester Client Database Management System Endpoint fetch_manager_details.php impro…

A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of t…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3733 — xuxueli xxl-job JobInfoController.java server-side request forgery

A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulati…

xxl-job | Remote | Server-Side Request Forgery
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3732 — Tenda F453 exeCommand strcpy stack-based overflow

A security vulnerability has been detected in Tenda F453 1.0.0.3. This affects the function strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to stack-based buffe…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.9 MEDIUM
CVE-2026-3731 — libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Na…

libssh | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3730 — itsourcecode Free Hotel Reservation System index.php sql injection

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performi…

free_hotel_reservation_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3729 — Tenda F453 PPTPDClient fromPptpUserAdd stack-based overflow

A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3728 — Tenda F453 setcfm fromSetCfm stack-based overflow

A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /goform/setcfm. This manipulation of the argument funcname/funcpara1 causes stack-bas…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3727 — Tenda F453 QuickIndex sub_3C6C0 stack-based overflow

A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function sub_3C6C0 of the file /goform/QuickIndex. The manipulation of the argument mit_linktype/PPPOEPassword results …

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
Showing 20 of 5027 Results