Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-3753 — SourceCodester Sales and Inventory System add_sales_print.php sql injection

A vulnerability has been found in SourceCodester Sales and Inventory System up to 1.0. The impacted element is an unknown function of the file /add_sales_print.php. Such manipulation of the argument …

sales_and_inventory_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.2 HIGH
CVE-2026-3752 — SourceCodester Employee Task Management System GET Parameter daily-task-report.php sql in…

A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handle…

employee_task_management_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.2 HIGH
CVE-2026-3751 — SourceCodester Employee Task Management System GET Parameter daily-attendance-report.php …

A vulnerability was detected in SourceCodester Employee Task Management System 1.0. Impacted is an unknown function of the file /daily-attendance-report.php of the component GET Parameter Handler. Th…

employee_task_management_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.8 MEDIUM
CVE-2026-3750 — ContiNew Admin Storage Management S3ClientFactory.java URI.create server-side request for…

A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of the file continew-system/src/main/java/top/continew/admin/system/factory/S3Clie…

continew_admin | Remote | Server-Side Request Forgery
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3749 — Bytedesk SVG File UploadRestService.java handleFileUpload unrestricted upload

A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestService.java …

Remote | Misconfiguration
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3748 — Bytedesk SVG File UploadRestController.java uploadFile unrestricted upload

A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java of the compo…

Remote | Misconfiguration
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3747 — itsourcecode University Management System add_result.php sql injection

A vulnerability was identified in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /add_result.php. Such manipulation of the argument su…

university_management_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3746 — SourceCodester Simple Responsive Tourism Website Login Login.php sql injection

A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of th…

simple_responsive_tourism_website | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3745 — code-projects Student Web Portal profile.php sql injection

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack …

student_web_portal | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3744 — code-projects Student Web Portal signup.php valreg_passwdation sql injection

A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql i…

student_web_portal | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3743 — YiFang CMS D_singlePageGroup.php update cross site scripting

A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation of the argument Name can lead to cross site script…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3742 — YiFang CMS D_singlePage.php update cross site scripting

A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument Title results in cro…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3741 — YiFang CMS D_friendLink.php update cross site scripting

A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3740 — itsourcecode University Management System admin_search_student.php sql injection

A weakness has been identified in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_search_student.php. This manipulation of the argument admin_search_…

university_management_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3739 — suitenumerique messages ThreadAccess serializers.py ThreadAccessSerializer improper authe…

A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/core/api/serializers.py of the component ThreadAcc…

Remote | Authentication
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3738 — SourceCodester Pet Grooming Management Software Financial Report improper authorization

A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Financial Report Page. The manipulation leads to improp…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3737 — SourceCodester Pet Grooming Management Software User Creation add_user.php improper autho…

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipu…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3736 — code-projects Simple Flight Ticket Booking System SearchResultRoundtrip.php sql injection

A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulati…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3735 — code-projects Simple Flight Ticket Booking System SearchResultOneway.php sql injection

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulati…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3734 — SourceCodester Client Database Management System Endpoint fetch_manager_details.php impro…

A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of t…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
Showing 20 of 5046 Results