Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-3794 — doramart DoraCMS Email API send improper authentication

A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper auth…

Remote | Authentication
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3793 — SourceCodester Sales and Inventory System GET Parameter sales_invoice1.php sql injection

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file sales_invoice1.php of the component GET Parameter Handler. This ma…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3792 — SourceCodester Sales and Inventory System GET Parameter purchase_invoice.php sql injection

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchase_invoice.php of the component GET Parameter Handler. The manipulation of t…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3791 — SourceCodester Sales and Inventory System Search dashboard.php sql injection

A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file dashboard.php of the component Search. The manipulati…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3790 — SourceCodester Sales and Inventory System POST Parameter check_supplier_details.php sql i…

A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file check_supplier_details.php of the component POST Paramet…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3789 — Bytedesk SpringAIGiteeRestController SpringAIGiteeRestService.java getModels server-side …

A vulnerability was detected in Bytedesk up to 1.3.9. Affected is the function getModels of the file source-code/src/main/java/com/bytedesk/ai/springai/providers/gitee/SpringAIGiteeRestService.java o…

Remote | Server-Side Request Forgery
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-3788 — Bytedesk SpringAIOpenrouterRestController SpringAIOpenrouterRestService.java getModels se…

A security vulnerability has been detected in Bytedesk up to 1.3.9. This impacts the function getModels of the file source-code/src/main/java/com/bytedesk/ai/springai/providers/openrouter/SpringAIOpe…

Remote | Server-Side Request Forgery
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.3 HIGH
CVE-2026-3787 — UltraVNC Windows Service cryptbase.dll uncontrolled search path

A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase.dll of the component Windows Service. This manipulation causes uncontrolled se…

ultravnc | Misconfiguration
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3786 — EasyCMS Request Parameter RbacuserAction.class.php sql injection

A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAction.class.php of the component Request Parameter Handler. The manipulatio…

easycms | Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3785 — EasyCMS Request Parameter RbacnodeAction.class.php sql injection

A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAction.class.php of the component Request Parameter Handler. The manipulation of …

easycms | Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3771 — SourceCodester/janobe Resort Reservation System accomodation.php sql injection

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads…

resort_reservation_system | Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.3 MEDIUM
CVE-2026-3770 — SourceCodester Computer Laboratory Management System cross-site request forgery

A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carr…

computer_laboratory_management_system | Remote | Cross-Site Request Forgery
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
9.0 HIGH
CVE-2026-3769 — Tenda F453 WrlclientSet stack-based overflow

A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function WrlclientSet of the file /goform/WrlclientSet. The manipulation of the argument GO results in stack-based bu…

f453_firmware | Remote | Memory Corruption
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
9.0 HIGH
CVE-2026-3768 — Tenda F453 WrlExtraSet formWrlExtraSet stack-based overflow

A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO l…

f453_firmware | Remote | Memory Corruption
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3767 — itsourcecode sanitize or validate this input teacher-attendance.php sql injection

A weakness has been identified in itsourcecode sanitize or validate this input 1.0. Affected is an unknown function of the file /admin/teacher-attendance.php. Executing a manipulation of the argument…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.1 MEDIUM
CVE-2026-3766 — SourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site s…

A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the…

web-based_pharmacy_product_management_system | Remote | Cross-Site Scripting
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3765 — itsourcecode University Management System att_single_view.php sql injection

A vulnerability was identified in itsourcecode University Management System 1.0. This affects an unknown function of the file /att_single_view.php. Such manipulation of the argument dt leads to sql i…

university_management_system | Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3764 — SourceCodester Client Database Management System superadmin_user_update.php improper auth…

A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /superadmin_user_update.php. This manipulation causes i…

Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
5.3 MEDIUM
CVE-2026-3763 — code-projects Simple Flight Ticket Booking System showhistory.php cross site scripting

A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown function of the file showhistory.php. The manipulation results in cross site scr…

Remote | Cross-Site Scripting
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3762 — SourceCodester Client Database Management System Endpoint superadmin_delete_manager.php i…

A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The m…

Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
Showing 20 of 4986 Results