VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

437 CVEsRSS

CVE-2026-90516High· 7.3PoC
2w ago

A vulnerability was found in SourceCodester School Registration and Fee System 1.0

A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql inj…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90515High· 7.3PoC
2w ago

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead …

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90514High· 7.3PoC
2w ago

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is poss…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90511Medium· 6.3PoC
2w ago

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface…

▾ TwilightGongShengyue · OnlineBooksEPSS 0.32%via NVD
CVE-2026-90581Medium· 6.3PoC
2w ago

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote explo…

▾ Twilightcym1102 · nginxWebUIEPSS 0.41%via NVD
CVE-2026-90574Medium· 6.3PoC
2w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The …

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90526High· 7.3PoC
2w ago

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Re…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90525Medium· 6.3PoC
2w ago

A weakness has been identified in itsourcecode Sales and Inventory System 1.0

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The atta…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90600Medium· 6.3PoC
2w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated rem…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90597Medium· 6.3PoC
2w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql injection. The att…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-85116Medium· 6.5
2w ago

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to exe…

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to exe…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-87925High· 7.3PoC
2w ago

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipula…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.43%via NVD
CVE-2026-88038Medium· 4.8
2w ago

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the …

▾ Sunlitcookies · cookiesEPSS 0.25%via NVD
CVE-2026-87921High· 7.3PoC
2w ago

A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_catego…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.43%via NVD
CVE-2026-85117Medium· 6.5
2w ago

The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes regi…

The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes regi…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-19855Medium· 6.5
2w ago

The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site execut…

The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site execut…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-80440Medium· 4.8
2w ago

The Hustle WordPress plugin before 7.8.14.2 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into the message it returns after submission, because the guard it applies can be defea…

The Hustle WordPress plugin before 7.8.14.2 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into the message it returns after submission, because the guard it applies can be defea…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-87572High· 8.3
2w ago

Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severi…

▾ Twilightgoogle · chromeEPSS 0.42%via NVD
CVE-2026-86675Medium· 6.3PoC
2w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely.…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-65669Critical· 9.6
2w ago

Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.

Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · SQL Server Management Studio 22EPSS 0.88%via NVD
CVE-2026-86667Medium· 4.7PoC
2w ago

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possi…

▾ Twilightaircheng-org · iWebShop-5EPSS 0.35%via NVD
CVE-2026-86518Medium· 6.3PoC
2w ago

A vulnerability has been found in code-projects Student Crud Operation 1.0

A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exp…

▾ Twilightcode-projects · Student Crud OperationEPSS 0.33%via NVD
CVE-2026-86517Medium· 6.3PoC
2w ago

A flaw has been found in itsourcecode Sales and Inventory System 1.0

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is pos…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86310Medium· 6.3PoC
2w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be …

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86309Medium· 6.3PoC
2w ago

A flaw has been found in itsourcecode Sales and Inventory System 1.0

A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. …

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86298High· 7.3PoC
2w ago

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is po…

▾ MidnightSourceCodester · Class and Exam Timetabling SystemEPSS 0.43%via NVD
CVE-2026-86295High· 8.3PoC
2w ago

A vulnerability was found in D-Link DIR-895L A1_102b07

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can…

▾ MidnightD-Link · DIR-895LEPSS 2.3%via NVD
CVE-2026-86291Medium· 6.3PoC
2w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be l…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86290High· 7.3PoC
2w ago

A weakness has been identified in SourceCodester Online Voting System 1.0

A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack ca…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-86282High· 7.3PoC
2w ago

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the compo…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.45%via NVD
CWE-74 vulnerabilities (CVEs) — page 5 · VulnSea