Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-3740 — itsourcecode University Management System admin_search_student.php sql injection

A weakness has been identified in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_search_student.php. This manipulation of the argument admin_search_…

university_management_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3739 — suitenumerique messages ThreadAccess serializers.py ThreadAccessSerializer improper authe…

A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/core/api/serializers.py of the component ThreadAcc…

Remote | Authentication
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3738 — SourceCodester Pet Grooming Management Software Financial Report improper authorization

A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Financial Report Page. The manipulation leads to improp…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3737 — SourceCodester Pet Grooming Management Software User Creation add_user.php improper autho…

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipu…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3736 — code-projects Simple Flight Ticket Booking System SearchResultRoundtrip.php sql injection

A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulati…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3735 — code-projects Simple Flight Ticket Booking System SearchResultOneway.php sql injection

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulati…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3734 — SourceCodester Client Database Management System Endpoint fetch_manager_details.php impro…

A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of t…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3733 — xuxueli xxl-job JobInfoController.java server-side request forgery

A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulati…

xxl-job | Remote | Server-Side Request Forgery
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3732 — Tenda F453 exeCommand strcpy stack-based overflow

A security vulnerability has been detected in Tenda F453 1.0.0.3. This affects the function strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to stack-based buffe…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3731 — libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Na…

libssh | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3730 — itsourcecode Free Hotel Reservation System index.php sql injection

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performi…

free_hotel_reservation_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3729 — Tenda F453 PPTPDClient fromPptpUserAdd stack-based overflow

A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3728 — Tenda F453 setcfm fromSetCfm stack-based overflow

A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /goform/setcfm. This manipulation of the argument funcname/funcpara1 causes stack-bas…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3727 — Tenda F453 QuickIndex sub_3C6C0 stack-based overflow

A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function sub_3C6C0 of the file /goform/QuickIndex. The manipulation of the argument mit_linktype/PPPOEPassword results …

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3726 — Tenda F453 webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow

A vulnerability has been found in Tenda F453 1.0.0.3. This affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack…

f453_firmware f453 | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3725 — 1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverConten…

A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/…

Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-3724 — SourceCodester Patients Waiting Area Queue Management System checkin.php improper authori…

A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /checkin.php. This manipulation of the argument patien…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-3723 — code-projects Simple Flight Ticket Booking System Admindelete.php sql injection

A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno …

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3721 — 1024-lab/lab1024 SmartAdmin Help Documentation HelpDocAddForm.java cross site scripting

A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/helpdoc/doma…

Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3720 — 1024-lab/lab1024 SmartAdmin Notice notice-form-drawer.vue cross site scripting

A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript/src/views/business/oa/notice/components/notice-fo…

Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
Showing 20 of 5035 Results