Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-3748 — Bytedesk SVG File UploadRestController.java uploadFile unrestricted upload

A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java of the compo…

Remote | Misconfiguration
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3747 — itsourcecode University Management System add_result.php sql injection

A vulnerability was identified in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /add_result.php. Such manipulation of the argument su…

university_management_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3746 — SourceCodester Simple Responsive Tourism Website Login Login.php sql injection

A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of th…

simple_responsive_tourism_website | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3745 — code-projects Student Web Portal profile.php sql injection

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack …

student_web_portal | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3744 — code-projects Student Web Portal signup.php valreg_passwdation sql injection

A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql i…

student_web_portal | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3743 — YiFang CMS D_singlePageGroup.php update cross site scripting

A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation of the argument Name can lead to cross site script…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3742 — YiFang CMS D_singlePage.php update cross site scripting

A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument Title results in cro…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-3741 — YiFang CMS D_friendLink.php update cross site scripting

A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads…

yifang | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3740 — itsourcecode University Management System admin_search_student.php sql injection

A weakness has been identified in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_search_student.php. This manipulation of the argument admin_search_…

university_management_system | Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3739 — suitenumerique messages ThreadAccess serializers.py ThreadAccessSerializer improper authe…

A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/core/api/serializers.py of the component ThreadAcc…

Remote | Authentication
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3738 — SourceCodester Pet Grooming Management Software Financial Report improper authorization

A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Financial Report Page. The manipulation leads to improp…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3737 — SourceCodester Pet Grooming Management Software User Creation add_user.php improper autho…

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipu…

pet_grooming_management_software | Remote | Authorization
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3736 — code-projects Simple Flight Ticket Booking System SearchResultRoundtrip.php sql injection

A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulati…

Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3735 — code-projects Simple Flight Ticket Booking System SearchResultOneway.php sql injection

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulati…

Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3734 — SourceCodester Client Database Management System Endpoint fetch_manager_details.php impro…

A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of t…

Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3733 — xuxueli xxl-job JobInfoController.java server-side request forgery

A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulati…

xxl-job | Remote | Server-Side Request Forgery
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3732 — Tenda F453 exeCommand strcpy stack-based overflow

A security vulnerability has been detected in Tenda F453 1.0.0.3. This affects the function strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to stack-based buffe…

f453_firmware | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
6.9 MEDIUM
CVE-2026-3731 — libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Na…

libssh | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3730 — itsourcecode Free Hotel Reservation System index.php sql injection

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performi…

Remote | Injection
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
9.0 HIGH
CVE-2026-3729 — Tenda F453 PPTPDClient fromPptpUserAdd stack-based overflow

A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-…

f453_firmware | Remote | Memory Corruption
Mar 08, 2026 Mar 09, 2026
Mar 08, 2026
Mar 09, 2026
Showing 20 of 5012 Results