VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

437 CVEsRSS

CVE-2026-11927Medium· 6.5
1w ago

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

▾ SunlitIBM · Verify Identity AccessEPSS 0.17%via NVD
CVE-2026-91848High· 7.3PoC
1w ago

A vulnerability was identified in WuzhiCMS up to 4.1.0

A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads t…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-91986Medium· 5.4PoC
1w ago

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof …

▾ TwilightGitoxideLabs · gitoxideEPSS 0.26%via NVD
CVE-2026-91004High· 7.3PoC
1w ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack c…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90880High· 7.4PoC
1w ago

A security flaw has been discovered in D-Link DSL-3782 2016-07-28

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr resul…

▾ MidnightD-Link · DSL-3782EPSS 1.9%via NVD
CVE-2026-90879High· 7.3PoC
1w ago

A vulnerability was identified in zyx0814 FilePress up to 3.0.1

A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql inj…

▾ Midnightzyx0814 · FilePressEPSS 0.43%via NVD
CVE-2026-90877High· 7.3PoC
1w ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injec…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90876High· 7.3PoC
1w ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql inject…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90855High· 7.3PoC
1w ago

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be init…

▾ MidnightSourceCodester · Online Food Ordering SystemEPSS 0.41%via NVD
CVE-2026-90854High· 7.3
1w ago

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injec…

▾ TwilightSourceCodester · Online Food Ordering SystemEPSS 0.41%via NVD
CVE-2026-90849High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User le…

▾ MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.43%via NVD
CVE-2026-90846High· 7.3PoC
1w ago

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is …

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90844High· 7.3PoC
1w ago

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injec…

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90841High· 7.3PoC
1w ago

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The m…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.43%via NVD
CVE-2026-41573High· 7.1
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protectio…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.50%via NVD
CVE-2026-55374Medium· 4.8
1w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the sch…

▾ Sunlitjleehr · canto-saas-apiEPSS 0.36%via NVD
CVE-2026-90809High· 7.3
1w ago

A vulnerability was identified in HKUDS nanobot up to 0.2.1

A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argu…

▾ TwilightHKUDS · nanobotEPSS 0.56%via NVD
CVE-2026-90805High· 7.3PoC
1w ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd ca…

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.43%via NVD
CVE-2026-90796Medium· 6.3PoC
1w ago

A vulnerability was identified in itsourcecode Leave Management System 1.0

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated r…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-90704Medium· 6.6PoC
1w ago

A vulnerability was found in D-Link DWR-M921 1.1.52

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitatio…

▾ TwilightD-Link · DWR-M921EPSS 2.3%via NVD
CVE-2026-90700Medium· 6.3PoC
1w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack ca…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90708High· 7.3PoC
1w ago

A weakness has been identified in Yot CMS up to 3.3.1

A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injectio…

▾ MidnightYot · CMSEPSS 0.41%via NVD
CVE-2026-90709Medium· 4.7PoC
1w ago

A security vulnerability has been detected in Yot CMS up to 3.3.1

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code inje…

▾ TwilightYot · CMSEPSS 0.41%via NVD
CVE-2026-90789High· 7.3PoC
1w ago

A weakness has been identified in itsourcecode Leave Management System 1.0

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The a…

▾ Midnightitsourcecode · Leave Management SystemEPSS 0.43%via NVD
CVE-2026-90701High· 7.3PoC
1w ago

A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argumen…

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.43%via NVD
CVE-2026-47256Medium· 5.3PoC
1w ago

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…

▾ Twilightopen-telemetry · opentelemetry-collector-contribEPSS 0.44%via NVD
CVE-2026-90496Medium· 4.7PoC
2w ago

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handle…

▾ TwilightFengoffice · Feng OfficeEPSS 0.33%via NVD
CVE-2026-90495High· 7.3PoC
2w ago

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of th…

▾ MidnightFengoffice · Feng OfficeEPSS 0.41%via NVD
CVE-2026-90491Medium· 6.3PoC
2w ago

A weakness has been identified in sanjevirau gsubs up to 1.0.3

A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code inj…

▾ Twilightsanjevirau · gsubsEPSS 0.42%via NVD
CVE-2026-90488Medium· 6.3PoC
2w ago

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection.…

▾ TwilightXuxueli · xxl-jobEPSS 0.39%via NVD
CWE-74 vulnerabilities (CVEs) — page 4 · VulnSea