VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

437 CVEsRSS

CVE-2026-86171Medium· 6.3PoC
3w ago

A security vulnerability has been detected in DefaultFuction CRM 1.0.0

A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed fro…

▾ TwilightDefaultFuction · CRMEPSS 0.32%via NVD
CVE-2026-86170Medium· 6.3PoC
3w ago

A weakness has been identified in DefaultFuction CRM 1.0.0

A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried…

▾ TwilightDefaultFuction · CRMEPSS 0.32%via NVD
CVE-2026-86168High· 7.3PoC
3w ago

A security flaw has been discovered in code-projects Content Management System 1.0

A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can b…

▾ Midnightcode-projects · Content Management SystemEPSS 0.43%via NVD
CVE-2026-86164Medium· 6.3PoC
3w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in sql injection. The attack may be perfor…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86163Medium· 6.3PoC
3w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carr…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86162High· 7.3PoC
3w ago

A vulnerability was determined in SourceCodester Online Voting System 1.0

A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can b…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-86161High· 7.3PoC
3w ago

A vulnerability was found in SourceCodester Online Voting System 1.0

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-86160High· 7.3PoC
3w ago

A vulnerability has been found in SourceCodester Online Voting System 1.0

A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack ma…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-86159High· 7.3PoC
3w ago

A flaw has been found in SourceCodester Online Voting System 1.0

A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. Th…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-85516High· 7.3PoC
3w ago

code-projects Vehicle Management System busprofile.php sql injection

A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possibl…

▾ Midnightcode-projects · Vehicle Management SystemEPSS 0.43%via CVEORG
CVE-2026-85402High· 7.3PoC
3w ago

code-projects Doctor Appointment System booking.php sql injection

A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be la…

▾ Midnightcode-projects · Doctor Appointment SystemEPSS 0.43%via CVEORG
CVE-2026-85383Medium· 6.3PoC
3w ago

itsourcecode Sales and Inventory System inv_del.php sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be ex…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via CVEORG
CVE-2026-85643Medium· 4.7PoC
3w ago

A flaw has been found in code-projects Online Shopping System 1.0

A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performe…

▾ Twilightcode-projects · Online Shopping SystemEPSS 0.35%via NVD
CVE-2026-85399High· 7.3PoC
3w ago

A security flaw has been discovered in code-projects Hospital Information System 1.0

A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument…

▾ Midnightcode-projects · Hospital Information SystemEPSS 0.43%via NVD
CVE-2026-85205Medium· 6.3
3w ago

A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0

A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argum…

▾ Sunlititsourcecode · Online Medicine Delivery SystemEPSS 0.33%via NVD
CVE-2026-85225High· 7.3
3w ago

A vulnerability was identified in code-projects Doctor Appointment System 1.0

A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initi…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-85137High· 7.3
3w ago

A security vulnerability has been detected in SeaCMS up to 13.6

A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The atta…

▾ TwilightEPSS 0.52%via NVD
GHSA-wwv5-g3v4-889xLow
3w ago

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_…

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

▾ Sunlittornado · tornadovia OSV
CVE-2026-77353Medium· 4.6
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequ…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-82545Medium· 6.3
4w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82541Medium· 6.3
4w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. The manipulation of the argument ID results in sql injection.…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82540Medium· 6.3
4w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82485Medium· 6.3
4w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The a…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82484Medium· 6.3
4w ago

A flaw has been found in itsourcecode Sales and Inventory System 1.0

A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82424Medium· 6.3
4w ago

A weakness has been identified in PHPGurukul Student Information System 1.0

A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-82422Medium· 6.3
4w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql injection. The attack may be launched …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82421Medium· 6.3
4w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The attack may be init…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-81523Medium· 4.4
1mo ago

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selectio…

▾ Sunlitmongodb · libmongocryptEPSS 0.10%via NVD
CVE-2026-65646Critical· 9.9
1mo ago

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

▾ MidnightWebPros · PleskEPSS 0.70%via CVEORG
CVE-2026-81203High· 7.3
1mo ago

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is pos…

▾ TwilightEPSS 0.43%via NVD
CWE-74 vulnerabilities (CVEs) — page 7 · VulnSea