CWE-74
CVEs classified under CWE-74, newest first.
438 CVEsRSS
CVE-2025-10596High· 7.3A vulnerability was found in SourceCodester Online Exam Form Submission 1.0
A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument usn results in sql injection. The attack can be launched remotely. The exp…
CVE-2025-10595Medium· 6.3A vulnerability has been found in SourceCodester Online Student File Management System 1.0
A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/delete_user.php. The manipulation of the argument user_id leads to sql in…
CVE-2025-10594Medium· 6.3A flaw has been found in SourceCodester Online Student File Management System 1.0
A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_student.php. Executing manipulation of the argument stud_id can lead …
CVE-2025-10593Medium· 6.3A vulnerability was detected in SourceCodester Online Student File Management System 1.0
A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It…
CVE-2025-10592Medium· 6.3A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0
A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search…
CVE-2025-10210Medium· 6.3PoCA weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0
A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launc…
CVE-2025-10012Medium· 6.3PoCA security vulnerability has been detected in Portabilis i-Educar up to 2.10
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injectio…
CVE-2025-9770High· 7.3A weakness has been identified in Campcodes Hospital Management System 1.0
A weakness has been identified in Campcodes Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Dashboard Login. This manipulation of the argument Password…
CVE-2025-9767High· 7.3A vulnerability was determined in itsourcecode Sports Management System 1.0
A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /Admin/sporttype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be exec…
CVE-2025-9766High· 7.3A vulnerability was found in itsourcecode Sports Management System 1.0
A vulnerability was found in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/facilitator.php. Performing manipulation of the argument code results in sql injection. Remote exploit…
CVE-2025-9765High· 7.3A vulnerability has been found in itsourcecode Sports Management System 1.0
A vulnerability has been found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/tournament_details.php. Such manipulation of the argument ID leads to sql injection. The attack m…
CVE-2025-9606Medium· 6.3PoCA vulnerability was detected in Portabilis i-Educar up to 2.10
A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql…
CVE-2025-9594High· 7.3A vulnerability has been found in itsourcecode Apartment Management System 1.0
A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /report/complain_info.php. The manipulation of the argument vid leads to sql injection. The attack is…
CVE-2025-9593High· 7.3A flaw has been found in itsourcecode Apartment Management System 1.0
A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/unit_status_info.php. Executing manipulation of the argument usid can lead to sql injection. The attack can be exe…
CVE-2025-9592High· 7.3A vulnerability was detected in itsourcecode Apartment Management System 1.0
A vulnerability was detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/bill_info.php. Performing manipulation of the argument vid results in sql injection. Remote expl…
CVE-2025-9586Medium· 6.3A vulnerability was identified in Comfast CF-N1 2.6.0
A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads to command injection. The attack may be perfo…
CVE-2025-9585Medium· 6.3A vulnerability was determined in Comfast CF-N1 2.6.0
A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of the argument portal_delete_picname causes command injection. The attack is possi…
CVE-2025-9584Medium· 6.3A vulnerability was found in Comfast CF-N1 2.6.0
A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of the argument interface/display_name results in command injection. The attack …
CVE-2025-9583Medium· 6.3A vulnerability has been found in Comfast CF-N1 2.6.0
A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to command injection. Remote exploitation of the attack is possible. T…
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0
A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command injection. The attack may be launched remotely. The expl…
CVE-2025-9581Medium· 6.3A vulnerability was detected in Comfast CF-N1 2.6.0
A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in command injection. The attack may be initiated remo…
CVE-2025-9531Medium· 6.3PoCA vulnerability was detected in Portabilis i-Educar up to 2.10
A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Module. Performing a manipulation of the argument cod_agenda results in sql injecti…
CVE-2025-9236Medium· 6.3PoCA vulnerability has been found in Portabilis i-Educar up to 2.10
A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descri…
CVE-2025-24291Medium· 6.1The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the…
CVE-2025-43955Low· 2.2TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression
TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes t…
CVE-2023-7299Medium· 6.3A vulnerability was found in DataGear up to 4.60
A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the argument sql leads to sql injection. The attack can be i…
CVE-2023-4548Medium· 6.3PoCA vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3
A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql inje…
CVE-2023-33234High· 7.2Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permi…
Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permi…
CVE-2023-2378High· 7.2A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This manipulation of the argument suffix-rate-up causes command injection. The attack may be…
CVE-2023-2377High· 7.2A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command injection. The at…