CWE-74
CVEs classified under CWE-74, newest first.
437 CVEsRSS
CVE-2026-11927Medium· 6.5IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
CVE-2026-91848High· 7.3PoCA vulnerability was identified in WuzhiCMS up to 4.1.0
A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads t…
CVE-2026-91986Medium· 5.4PoCgitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof …
CVE-2026-91004High· 7.3PoCA vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack c…
CVE-2026-90880High· 7.4PoCA security flaw has been discovered in D-Link DSL-3782 2016-07-28
A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr resul…
CVE-2026-90879High· 7.3PoCA vulnerability was identified in zyx0814 FilePress up to 3.0.1
A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql inj…
CVE-2026-90877High· 7.3PoCA vulnerability was found in SourceCodester Online Faculty Clearance System 1.0
A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injec…
CVE-2026-90876High· 7.3PoCA vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql inject…
CVE-2026-90855High· 7.3PoCA weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0
A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be init…
CVE-2026-90854High· 7.3A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0
A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injec…
CVE-2026-90849High· 7.3PoCA security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User le…
CVE-2026-90846High· 7.3PoCA vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is …
CVE-2026-90844High· 7.3PoCA vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1
A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injec…
CVE-2026-90841High· 7.3PoCA security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0
A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The m…
CVE-2026-41573High· 7.1Open Access Management (OpenAM) is an access management solution
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protectio…
CVE-2026-55374Medium· 4.8canto-saas-api is a PHP library for interacting with the Canto SaaS API
canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the sch…
CVE-2026-90809High· 7.3A vulnerability was identified in HKUDS nanobot up to 0.2.1
A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argu…
CVE-2026-90805High· 7.3PoCA flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd ca…
CVE-2026-90796Medium· 6.3PoCA vulnerability was identified in itsourcecode Leave Management System 1.0
A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated r…
CVE-2026-90704Medium· 6.6PoCA vulnerability was found in D-Link DWR-M921 1.1.52
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitatio…
CVE-2026-90700Medium· 6.3PoCA security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack ca…
CVE-2026-90708High· 7.3PoCA weakness has been identified in Yot CMS up to 3.3.1
A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injectio…
CVE-2026-90709Medium· 4.7PoCA security vulnerability has been detected in Yot CMS up to 3.3.1
A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code inje…
CVE-2026-90789High· 7.3PoCA weakness has been identified in itsourcecode Leave Management System 1.0
A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The a…
CVE-2026-90701High· 7.3PoCA vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578
A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argumen…
CVE-2026-47256Medium· 5.3PoCOpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs
OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…
CVE-2026-90496Medium· 4.7PoCA vulnerability was found in Fengoffice Feng Office up to 3.11.13.11
A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handle…
CVE-2026-90495High· 7.3PoCA vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11
A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of th…
CVE-2026-90491Medium· 6.3PoCA weakness has been identified in sanjevirau gsubs up to 1.0.3
A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code inj…
CVE-2026-90488Medium· 6.3PoCA vulnerability was determined in Xuxueli xxl-job up to 3.4.2
A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection.…