VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

348 CVEsRSS

CVE-2026-90846High· 7.3PoC
6d ago

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is …

MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.26%via NVD
CVE-2026-90844High· 7.3PoC
6d ago

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injec…

MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.26%via NVD
CVE-2026-90841High· 7.3PoC
6d ago

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The m…

MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.27%via NVD
CVE-2026-41573High· 7.1
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protectio…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.36%via NVD
CVE-2026-55374Medium· 4.8
6d ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the sch…

Sunlitjleehr · canto-saas-apiEPSS 0.23%via NVD
CVE-2026-90809High· 7.3
1w ago

A vulnerability was identified in HKUDS nanobot up to 0.2.1

A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argu…

TwilightHKUDS · nanobotEPSS 0.33%via NVD
CVE-2026-90805High· 7.3PoC
1w ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd ca…

Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.26%via NVD
CVE-2026-90796Medium· 6.3PoC
1w ago

A vulnerability was identified in itsourcecode Leave Management System 1.0

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated r…

Twilightitsourcecode · Leave Management SystemEPSS 0.25%via NVD
CVE-2026-90704Medium· 6.6PoC
1w ago

A vulnerability was found in D-Link DWR-M921 1.1.52

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitatio…

TwilightD-Link · DWR-M921EPSS 1.5%via NVD
CVE-2026-90700Medium· 6.3PoC
1w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack ca…

Twilightitsourcecode · Sales and Inventory SystemEPSS 0.20%via NVD
CVE-2026-90708High· 7.3PoC
1w ago

A weakness has been identified in Yot CMS up to 3.3.1

A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injectio…

MidnightYot · CMSEPSS 0.25%via NVD
CVE-2026-90709Medium· 4.7PoC
1w ago

A security vulnerability has been detected in Yot CMS up to 3.3.1

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code inje…

TwilightYot · CMSEPSS 0.24%via NVD
CVE-2026-90789High· 7.3PoC
1w ago

A weakness has been identified in itsourcecode Leave Management System 1.0

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The a…

Midnightitsourcecode · Leave Management SystemEPSS 0.26%via NVD
CVE-2026-90701High· 7.3PoC
1w ago

A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argumen…

Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.41%via NVD
CVE-2026-47256Medium· 5.3PoC
1w ago

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…

Twilightopen-telemetry · opentelemetry-collector-contribEPSS 0.42%via NVD
CVE-2026-90496Medium· 4.7PoC
1w ago

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handle…

TwilightFengoffice · Feng OfficeEPSS 0.20%via NVD
CVE-2026-90495High· 7.3PoC
1w ago

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of th…

MidnightFengoffice · Feng OfficeEPSS 0.26%via NVD
CVE-2026-90491Medium· 6.3PoC
1w ago

A weakness has been identified in sanjevirau gsubs up to 1.0.3

A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code inj…

Twilightsanjevirau · gsubsEPSS 0.24%via NVD
CVE-2026-90488Medium· 6.3PoC
1w ago

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection.…

TwilightXuxueli · xxl-jobEPSS 0.23%via NVD
CVE-2026-90516High· 7.3PoC
1w ago

A vulnerability was found in SourceCodester School Registration and Fee System 1.0

A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql inj…

MidnightSourceCodester · School Registration and Fee SystemEPSS 0.41%via NVD
CVE-2026-90515High· 7.3PoC
1w ago

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead …

MidnightSourceCodester · School Registration and Fee SystemEPSS 0.26%via NVD
CVE-2026-90514High· 7.3PoC
1w ago

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is poss…

MidnightSourceCodester · School Registration and Fee SystemEPSS 0.26%via NVD
CVE-2026-90511Medium· 6.3PoC
1w ago

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface…

TwilightGongShengyue · OnlineBooksEPSS 0.19%via NVD
CVE-2026-90581Medium· 6.3PoC
1w ago

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote explo…

Twilightcym1102 · nginxWebUIEPSS 0.24%via NVD
CVE-2026-90574Medium· 6.3PoC
1w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The …

Twilightitsourcecode · Sales and Inventory SystemEPSS 0.32%via NVD
CVE-2026-90526High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Re…

MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90525Medium· 6.3PoC
1w ago

A weakness has been identified in itsourcecode Sales and Inventory System 1.0

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The atta…

Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90600Medium· 6.3PoC
1w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated rem…

Twilightitsourcecode · Sales and Inventory SystemEPSS 0.20%via NVD
CVE-2026-90597Medium· 6.3PoC
1w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql injection. The att…

Twilightitsourcecode · Sales and Inventory SystemEPSS 0.20%via NVD
CVE-2026-85116Medium· 6.5
1w ago

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to exe…

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to exe…

SunlitEPSS 0.18%via NVD
CWE-74 vulnerabilities (CVEs) — page 3 · VulnSea