CVE-2026-18782Critical· 9.8▾ MidnightImproper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex ME…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.
This issue affects Trex MES: through 2026-09-29.
trex_mes <= 2026-09-29Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-18783High· 8.8Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES
CVE-2025-14666High· 7.3A weakness has been identified in itsourcecode COVID Tracking System 1.0
CVE-2025-14667High· 7.3A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0
CVE-2025-14668High· 7.3A vulnerability was detected in campcodes Advanced Online Examination System 1.0
CVE-2025-14664High· 7.3A vulnerability was identified in Campcodes Supplier Management System 1.0
CVE-2025-10601High· 7.3A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0