CVE Vulnerability Database

Search and browse 234 known security vulnerabilities. Filter by severity, vendor, product, and year.

234 vulnerabilities found
CVE-2026-36941
2.7 low

Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php.

Apr 13, 2026
CVE-2026-36947
2.7 low

Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/admin/services/view_service.php.

Oretnom23 Computer And Mobile Repair Shop Management System Apr 13, 2026
CVE-2026-36946
2.7 low

Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php.

Oretnom23 Computer And Mobile Repair Shop Management System Apr 13, 2026
CVE-2026-36923
2.7 low

Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php.

Oretnom23 Cab Management System Apr 13, 2026
CVE-2026-36922
2.7 low

Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category.php.

Oretnom23 Cab Management System Apr 13, 2026
CVE-2026-36920
2.7 low

Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php.

Janobe Online Reviewer System Apr 13, 2026
CVE-2026-36919
2.7 low

Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php.

Janobe Online Reviewer System Apr 13, 2026
CVE-2026-36874
2.7 low

Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.

Razormist Basic Library System Apr 13, 2026
CVE-2026-36873
2.7 low

Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php.

Razormist Basic Library System Apr 13, 2026
CVE-2026-36872
2.7 low

Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php.

Razormist Basic Library System Apr 13, 2026
CVE-2025-15632
3.5 low

A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. U

Apr 13, 2026
CVE-2026-40109
3.1 low

Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux notification-controller does not validate the email claim of Google OIDC tokens used for Pub/Sub push authentication. This allows any vali

Apr 9, 2026
CVE-2026-40077
3.5 low

Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied system ID and proceed without further checks that the user should have access to that system. As a result, any authenticated user can access these routes for any system if they know t

Apr 9, 2026
CVE-2026-24661
3.7 low

Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611

Apr 9, 2026
CVE-2026-21388
3.7 low

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610

Apr 9, 2026
CVE-2025-69015
3.8 low

Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.2.

Dec 30, 2025
CVE-2025-15245
3.5 low

A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware Update Service. The manipulation of the argument DownloadFile results in path traversal. The attack must originate from the local network. The exploit has been made public and coul

Dlink Dcs-850L Firmware Dec 30, 2025
CVE-2025-15244
3.7 low

A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request Handler. The manipulation leads to race condition. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is said to be diff

Phpems Phpems Dec 30, 2025
CVE-2025-15242
3.1 low

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as dif

Phpems Phpems Dec 30, 2025
CVE-2025-15241
3.5 low

A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack rem

Dec 30, 2025
CVE-2025-15221
3.5 low

A flaw has been found in SohuTV CacheCloud up to 3.2.0. This vulnerability affects the function index of the file src/main/java/com/sohu/cache/web/controller/AppDataMigrateController.java. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has b

Sohu Cachecloud Dec 30, 2025
CVE-2025-15219
3.5 low

A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. Affected by this issue is the function doMachineList/doPodList of the file src/main/java/com/sohu/cache/web/controller/MachineManageController.java. The manipulation leads to cross site scripting. The attack may be initiate

Sohu Cachecloud Dec 30, 2025
CVE-2025-15214
2.4 low

A vulnerability was found in Campcodes Park Ticketing System 1.0. The impacted element is the function save_pricing of the file admin_class.php. The manipulation of the argument name/ride results in cross site scripting. The attack may be performed from remote. The exploit has been made public and c

Campcodes Park Ticketing System Dec 30, 2025
CVE-2025-15284
3.7 low

Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply unif

Qs Project Qs Dec 29, 2025