Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-3737 — SourceCodester Pet Grooming Management Software User Creation add_user.php improper autho…

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipu…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3736 — code-projects Simple Flight Ticket Booking System SearchResultRoundtrip.php sql injection

A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulati…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3735 — code-projects Simple Flight Ticket Booking System SearchResultOneway.php sql injection

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulati…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3734 — SourceCodester Client Database Management System Endpoint fetch_manager_details.php impro…

A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of t…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3733 — xuxueli xxl-job JobInfoController.java server-side request forgery

A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulati…

xxl-job | Remote | Server-Side Request Forgery
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3732 — Tenda F453 exeCommand strcpy stack-based overflow

A security vulnerability has been detected in Tenda F453 1.0.0.3. This affects the function strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to stack-based buffe…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3731 — libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Na…

libssh | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3730 — itsourcecode Free Hotel Reservation System index.php sql injection

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performi…

free_hotel_reservation_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3729 — Tenda F453 PPTPDClient fromPptpUserAdd stack-based overflow

A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3728 — Tenda F453 setcfm fromSetCfm stack-based overflow

A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /goform/setcfm. This manipulation of the argument funcname/funcpara1 causes stack-bas…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3727 — Tenda F453 QuickIndex sub_3C6C0 stack-based overflow

A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function sub_3C6C0 of the file /goform/QuickIndex. The manipulation of the argument mit_linktype/PPPOEPassword results …

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3726 — Tenda F453 webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow

A vulnerability has been found in Tenda F453 1.0.0.3. This affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3725 — 1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverConten…

A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/…

Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3724 — SourceCodester Patients Waiting Area Queue Management System checkin.php improper authori…

A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /checkin.php. This manipulation of the argument patien…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3723 — code-projects Simple Flight Ticket Booking System Admindelete.php sql injection

A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno …

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3721 — 1024-lab/lab1024 SmartAdmin Help Documentation HelpDocAddForm.java cross site scripting

A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/helpdoc/doma…

Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3720 — 1024-lab/lab1024 SmartAdmin Notice notice-form-drawer.vue cross site scripting

A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript/src/views/business/oa/notice/components/notice-fo…

Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.5 MEDIUM
CVE-2026-3719 — Tsinghua Unigroup Electronic Archives System downLoad path traversal

A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the file /System/Cms/downLoad. The manipulation of the …

electronic_archives_system | Remote | Path Traversal
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
4.8 MEDIUM
CVE-2026-3716 — Wavlink WL-WN579X3-C adm.cgi sub_401AD4 cross site scripting

A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This vulnerability affects the function sub_401AD4 of the file /cgi-bin/adm.cgi. Executing a manipulation of the argument Hostname can l…

Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3715 — Wavlink WL-WN579X3-C firewall.cgi sub_40139C stack-based overflow

A vulnerability was found in Wavlink WL-WN579X3-C 231124. This affects the function sub_40139C of the file /cgi-bin/firewall.cgi. Performing a manipulation of the argument del_flag results in stack-b…

Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
Showing 20 of 5050 Results