CWE-74
CVEs classified under CWE-74, newest first.
437 CVEsRSS
CVE-2026-86171Medium· 6.3PoCA security vulnerability has been detected in DefaultFuction CRM 1.0.0
A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed fro…
CVE-2026-86170Medium· 6.3PoCA weakness has been identified in DefaultFuction CRM 1.0.0
A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried…
CVE-2026-86168High· 7.3PoCA security flaw has been discovered in code-projects Content Management System 1.0
A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can b…
CVE-2026-86164Medium· 6.3PoCA security flaw has been discovered in itsourcecode Sales and Inventory System 1.0
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in sql injection. The attack may be perfor…
CVE-2026-86163Medium· 6.3PoCA vulnerability was identified in itsourcecode Sales and Inventory System 1.0
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carr…
CVE-2026-86162High· 7.3PoCA vulnerability was determined in SourceCodester Online Voting System 1.0
A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can b…
CVE-2026-86161High· 7.3PoCA vulnerability was found in SourceCodester Online Voting System 1.0
A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote…
CVE-2026-86160High· 7.3PoCA vulnerability has been found in SourceCodester Online Voting System 1.0
A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack ma…
CVE-2026-86159High· 7.3PoCA flaw has been found in SourceCodester Online Voting System 1.0
A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. Th…
CVE-2026-85516High· 7.3PoCcode-projects Vehicle Management System busprofile.php sql injection
A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possibl…
CVE-2026-85402High· 7.3PoCcode-projects Doctor Appointment System booking.php sql injection
A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be la…
CVE-2026-85383Medium· 6.3PoCitsourcecode Sales and Inventory System inv_del.php sql injection
A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be ex…
CVE-2026-85643Medium· 4.7PoCA flaw has been found in code-projects Online Shopping System 1.0
A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performe…
CVE-2026-85399High· 7.3PoCA security flaw has been discovered in code-projects Hospital Information System 1.0
A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument…
CVE-2026-85205Medium· 6.3A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0
A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argum…
CVE-2026-85225High· 7.3A vulnerability was identified in code-projects Doctor Appointment System 1.0
A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initi…
CVE-2026-85137High· 7.3A security vulnerability has been detected in SeaCMS up to 13.6
A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The atta…
GHSA-wwv5-g3v4-889xLowTornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_…
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
CVE-2026-77353Medium· 4.6Wallos is an open-source, self-hostable personal subscription tracker
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequ…
CVE-2026-82545Medium· 6.3A vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated …
CVE-2026-82541Medium· 6.3A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. The manipulation of the argument ID results in sql injection.…
CVE-2026-82540Medium· 6.3A vulnerability was identified in itsourcecode Sales and Inventory System 1.0
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the …
CVE-2026-82485Medium· 6.3A vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The a…
CVE-2026-82484Medium· 6.3A flaw has been found in itsourcecode Sales and Inventory System 1.0
A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. …
CVE-2026-82424Medium· 6.3A weakness has been identified in PHPGurukul Student Information System 1.0
A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection…
CVE-2026-82422Medium· 6.3A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql injection. The attack may be launched …
CVE-2026-82421Medium· 6.3A vulnerability was identified in itsourcecode Sales and Inventory System 1.0
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The attack may be init…
CVE-2026-81523Medium· 4.4A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization
A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selectio…
CVE-2026-65646Critical· 9.9Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
CVE-2026-81203High· 7.3A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is pos…