Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-3767 — itsourcecode sanitize or validate this input teacher-attendance.php sql injection

A weakness has been identified in itsourcecode sanitize or validate this input 1.0. Affected is an unknown function of the file /admin/teacher-attendance.php. Executing a manipulation of the argument…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.1 MEDIUM
CVE-2026-3766 — SourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site s…

A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the…

Remote | Cross-Site Scripting
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3765 — itsourcecode University Management System att_single_view.php sql injection

A vulnerability was identified in itsourcecode University Management System 1.0. This affects an unknown function of the file /att_single_view.php. Such manipulation of the argument dt leads to sql i…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3764 — SourceCodester Client Database Management System superadmin_user_update.php improper auth…

A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /superadmin_user_update.php. This manipulation causes i…

Remote | Authorization
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.3 MEDIUM
CVE-2026-3763 — code-projects Simple Flight Ticket Booking System showhistory.php cross site scripting

A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown function of the file showhistory.php. The manipulation results in cross site scr…

Remote | Cross-Site Scripting
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3762 — SourceCodester Client Database Management System Endpoint superadmin_delete_manager.php i…

A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The m…

Remote | Authorization
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.5 MEDIUM
CVE-2026-3761 — SourceCodester Client Database Management System Endpoint superadmin_user_delete.php impr…

A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /superadmin_user_delete.php of the component Endpoint. Executing …

Remote | Authorization
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3760 — itsourcecode University Management System view_result.php sql injection

A vulnerability was detected in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /view_result.php. Performing a manipulation of the argument seme res…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3759 — projectworlds Online Art Gallery Shop adminHome.php sql injection

A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm lead…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3758 — projectworlds Online Art Gallery Shop adminHome.php sql injection

A weakness has been identified in projectworlds Online Art Gallery Shop 1.0. Affected by this issue is some unknown functionality of the file /admin/adminHome.php. This manipulation of the argument I…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3757 — projectworlds Online Art Gallery Shop pass sql injection

A security flaw has been discovered in projectworlds Online Art Gallery Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /?pass=1. The manipulation of the argument fnm…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3756 — SourceCodester Sales and Inventory System check_item_details.php sql injection

A vulnerability was identified in SourceCodester Sales and Inventory System up to 1.0. Affected is an unknown function of the file /check_item_details.php. The manipulation of the argument stock_name…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3755 — SourceCodester Sales and Inventory System POST check_customer_details.php sql injection

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /check_customer_details.php of the component POST Handler. Executing a ma…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3754 — SourceCodester Sales and Inventory System add_stock.php sql injection

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /add_stock.php. Performing a manipulation of the argument cost results in sql …

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3753 — SourceCodester Sales and Inventory System add_sales_print.php sql injection

A vulnerability has been found in SourceCodester Sales and Inventory System up to 1.0. The impacted element is an unknown function of the file /add_sales_print.php. Such manipulation of the argument …

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.8 MEDIUM
CVE-2026-3752 — SourceCodester Employee Task Management System GET Parameter daily-task-report.php sql in…

A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handle…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.8 MEDIUM
CVE-2026-3751 — SourceCodester Employee Task Management System GET Parameter daily-attendance-report.php …

A vulnerability was detected in SourceCodester Employee Task Management System 1.0. Impacted is an unknown function of the file /daily-attendance-report.php of the component GET Parameter Handler. Th…

employee_task_management_system | Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.8 MEDIUM
CVE-2026-3750 — ContiNew Admin Storage Management S3ClientFactory.java URI.create server-side request for…

A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of the file continew-system/src/main/java/top/continew/admin/system/factory/S3Clie…

continew_admin | Remote | Server-Side Request Forgery
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3749 — Bytedesk SVG File UploadRestService.java handleFileUpload unrestricted upload

A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestService.java …

Remote | Misconfiguration
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3748 — Bytedesk SVG File UploadRestController.java uploadFile unrestricted upload

A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java of the compo…

Remote | Misconfiguration
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
Showing 20 of 4984 Results