By weakness (CWE)

CWE-74: related vulnerabilities

CVEs classified under CWE-74. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

264 published vulnerabilities · page 1 of 3

  • CVE-2026-12186HIGH 8.8

    GL.iNet's GL-MT3000 router contains a command injection vulnerability in its Tor proxy configuration feature. An authenticated attacker can manipulate the replace_country function to execute arbitrary system commands remotely. The vendor has released version 4.7 as a fix. This is a serious issue affecting routers running versions up to 4.4.5, though it requires valid login credentials to exploit.

  • CVE-2026-12187HIGH 8.8

    GL.iNet GL-MT3000 routers running firmware versions up to 4.4.5 contain a command injection vulnerability in the online firmware upgrade mechanism. An authenticated attacker can exploit this flaw to execute arbitrary commands on the device with full system privileges. The vulnerability has been publicly disclosed and proof-of-concept code is available, increasing the risk of active exploitation. GL.iNet has released a patch in version 4.7 that resolves the issue.

  • CVE-2026-47162HIGH 8.8

    Vim, the popular open-source text editor, contains a code injection vulnerability in its netrw file browser plugin. When you browse directories in Vim, it saves a history of the paths you've visited to a file called .netrwhist. An attacker can craft a malicious directory name containing special characters that, when saved to this history file, breaks out of the intended string format and tricks Vim into executing arbitrary commands the next time you open the editor. This could allow an attacker to run malicious code on your system if you cd into or browse a directory with a carefully crafted name. The vulnerability is fixed in Vim version 9.2.0495 and later.

  • CVE-2026-7770HIGH 8.8

    IBM i Access Client Solutions (ACS) versions 1.1.5.0 through 1.1.9.12 contain a remote code execution vulnerability when the software is configured to receive requests from IBM i Navigator. An authenticated attacker can exploit this flaw to execute arbitrary code on the affected system, potentially compromising the entire environment. This is a serious vulnerability affecting a core IBM i administration tool.

  • CVE-2026-50574HIGH 8.3

    yt-dlp, a popular command-line tool for downloading audio and video from the web, contains a security flaw that allows attackers to write arbitrary files to a system when the aria2c external downloader is used with fragmented video formats like HLS or DASH streams. On Windows, this can lead to immediate code execution; on other platforms, malicious code would execute the next time yt-dlp runs. The vulnerability was patched in version 2026.06.09.

  • CVE-2026-55427HIGH 8.3

    Coder, a platform that helps organizations set up remote development environments, has a vulnerability in versions prior to 2.29.7, 2.32.7, 2.33.8, and 2.34.2. The `coder config-ssh` command copies SSH configuration settings from the Coder server to a developer's local SSH config file without properly validating those settings. An attacker who controls or compromises the Coder server could inject malicious SSH configuration directives—including arbitrary commands—by embedding special characters into fields that get written to the user's SSH config. This could lead to remote code execution when the developer connects via SSH. Exploitation requires either server compromise, administrator access to specific settings, or a network position to intercept communications.

  • CVE-2026-11311HIGH 8.1

    NGINX Gateway Fabric contains a configuration injection vulnerability that allows authenticated users with permission to create or modify certain Kubernetes Custom Resources to inject malicious NGINX directives. By crafting specially-formatted values in the serverTokens field (NginxProxy resource) or extraAuthArgs field (AuthenticationFilter resource), an attacker can insert arbitrary configuration that alters how NGINX processes requests. The vulnerability requires valid cluster credentials and appropriate RBAC permissions to exploit, making it a control-plane risk rather than a direct data-plane exposure.

  • CVE-2026-42835HIGH 8.1

    Microsoft Teams for Android contains an injection vulnerability that allows an authenticated attacker to extract sensitive information from the application. The flaw stems from improper handling of special characters in data passed to downstream components, creating a pathway for unauthorized data disclosure. An attacker must already have valid credentials to exploit this vulnerability, but once authenticated, they can access information without triggering user interaction or modifying data.

  • CVE-2026-45344HIGH 8.1

    LinkAce, a self-hosted web link archival tool, contains a critical vulnerability in its initial setup wizard that allows remote attackers to inject malicious database credentials. When an attacker provides specially crafted input during the database configuration step on a fresh LinkAce instance, the application writes unsanitized data into the .env configuration file. By controlling the database and injecting mail configuration variables, an attacker can execute arbitrary commands when the application attempts to send emails. This flaw affects all versions prior to 2.5.6.

  • CVE-2026-50107HIGH 8.1

    NGINX Gateway Fabric contains a configuration injection vulnerability in how it processes user-supplied access log format settings. When an authenticated user modifies the NginxProxy resource definition, their input is directly inserted into NGINX configuration files without proper validation. An attacker with control-plane access can inject malicious NGINX directives, potentially compromising system integrity and confidentiality. This is a control-plane issue, not a data-plane vulnerability, but it creates a significant security boundary violation for multi-tenant or role-based access control scenarios.

  • CVE-2026-8795HIGH 7.8

    Rapid7 Velociraptor contains a vulnerability where specially crafted evidence collections can inject malicious code into YAML configuration files. When a security analyst processes a compromised collection using Velociraptor's remapping feature, arbitrary commands execute on their workstation with full permissions. The attack requires an attacker to control a collection ZIP file (obtained through network compromise or social engineering) and a user to run a specific analysis command. This is a local privilege escalation risk for incident response teams.

  • CVE-2026-41234HIGH 7.6

    Froxlor, an open-source server administration platform, contains a vulnerability in its DNS management API that allows authenticated users to break out of TXT record fields and inject malicious DNS directives. An attacker with customer-level DNS editing permissions can inject newline characters into TXT record values, causing them to span multiple lines in the generated BIND zone file. This allows injection of arbitrary BIND directives like `$INCLUDE` or `$GENERATE`, as well as unauthorized DNS records (A, MX, CNAME entries). The vulnerability affects all versions prior to 2.3.7 and is notable because it bypassed an earlier attempted fix for similar issues in other record types.

  • CVE-2026-14249HIGH 7.5

    The Request a Quote plugin for WordPress contains a critical flaw that allows unauthenticated attackers to execute arbitrary PHP functions on affected servers. The vulnerability exists in the emd_delete_file AJAX handler, which accepts a user-supplied path parameter, extracts a function name from it, and then executes that function dynamically. Although the handler includes a nonce check (a WordPress security token), the nonce is publicly exposed in the page source via wp_localize_script, making it accessible to attackers. This means an attacker can craft a request to run dangerous PHP functions like phpinfo() to steal configuration data and credentials, or invoke other destructive built-in functions to compromise the server.

  • CVE-2026-55404HIGH 7.5

    yt-dlp and youtube-dl are popular command-line tools for downloading audio and video from the web. When using shortcut-creation options (--write-link, --write-url-link, or --write-desktop-link), these tools can be tricked into generating malicious shortcut files if a video source contains specially crafted metadata. On Windows, an attacker can inject file:// URIs that execute commands when a user opens the shortcut; on Linux, injected newlines in desktop entry files can similarly lead to command execution. Version 2026.7.4 and later address this by properly validating and escaping metadata before writing shortcut files.

  • CVE-2026-10110HIGH 7.3

    A SQL injection vulnerability exists in code-projects Student Details Management System version 1.0 affecting the /index.php file. An attacker can manipulate the 'roll' parameter to inject arbitrary SQL commands, potentially accessing, modifying, or deleting sensitive student records. The vulnerability requires no authentication and can be exploited remotely over the network. Public exploit code is already available, increasing the risk of active exploitation.

  • CVE-2026-10111HIGH 7.3

    A SQL injection vulnerability exists in the Login Page of sambitraj STUDENT-MANAGEMENT-SYSTEM version 1.0. An attacker can manipulate the email parameter during login to inject malicious SQL commands, potentially compromising the database. The vulnerability requires no authentication or user interaction and can be exploited remotely. Exploit code has already been published publicly, elevating the practical risk.

  • CVE-2026-10178HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Music Site version 1.0 that allows unauthenticated remote attackers to inject malicious SQL commands through the ID parameter in the admin album editing interface. The flaw permits reading, modifying, or deleting database records without authorization. Public exploit code is available, elevating immediate risk.

  • CVE-2026-10184HIGH 7.3

    SourceCodester Hospitals Patient Records Management System version 1.0 contains a SQL injection vulnerability in its user deletion function. An attacker can send a specially crafted request to the /classes/Users.php endpoint that manipulates the ID parameter, allowing unauthorized database queries. Because this flaw requires no authentication and can be exploited over the network, it poses a significant risk to hospital operations and patient data confidentiality.

  • CVE-2026-10185HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System version 1.0. An attacker can send a malicious request to the /classes/Users.php file with a crafted ID parameter that causes the application to execute unintended database commands. No authentication is required, and the vulnerability is accessible over the network. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-10186HIGH 7.3

    CVE-2026-10186 is a SQL injection vulnerability in code-projects Online Hospital Management System version 1.0. An attacker can craft a malicious request to the /patient.php file, manipulating the 'editid' parameter to execute arbitrary SQL commands against the backend database. No authentication is required, and the exploit can be triggered remotely over the network. Public exploit details are available, increasing the practical risk of active exploitation.

  • CVE-2026-10208HIGH 7.3

    A SQL injection vulnerability exists in the Online Hospital Management System version 1.php, specifically in the login_user function of login_1.php. An attacker can manipulate the Username parameter during login to inject malicious SQL commands. This allows unauthorized access and data compromise without requiring authentication or user interaction. The vulnerability is remotely exploitable and public exploit code has already been released.

  • CVE-2026-10220HIGH 7.3

    NousResearch's hermes-agent application contains a vulnerability in how it handles plugin skill requests. An attacker can send specially crafted input to the skill_view function that gets injected into backend operations, potentially compromising the confidentiality, integrity, and availability of the affected system. The vulnerability is network-accessible, requires no authentication, and can be triggered without user interaction. Because exploit details have been publicly disclosed, the attack surface is visible to potential adversaries.

  • CVE-2026-10221HIGH 7.3

    A code injection vulnerability exists in NousResearch's hermes-agent software, affecting versions up to 0.12.0. The flaw resides in the context compression function and allows remote attackers to inject malicious code without requiring authentication or user interaction. Public exploit code is available, increasing the practical risk of exploitation.

  • CVE-2026-10225HIGH 7.3

    A SQL injection vulnerability exists in raisulislamg4's student management system (PHP-based). An attacker can manipulate the Username parameter in the login_check.php file to inject malicious SQL commands. The vulnerability is network-accessible, requires no authentication, and doesn't require user interaction. Exploit code is publicly available. The project uses a rolling release model, making it difficult to track specific patched versions.

  • CVE-2026-10226HIGH 7.3

    A SQL injection vulnerability exists in the raisulislamg4 student management system (a PHP-based open-source project). An attacker can manipulate parameters in the delete.php file—specifically user_id, course_id, teacher_id, student_id, or application_id—to inject malicious SQL commands. This can be exploited remotely without authentication or user interaction, allowing an attacker to read, modify, or delete database records. Proof-of-concept code has been published, increasing the risk of active exploitation.

  • CVE-2026-10227HIGH 7.3

    A SQL injection vulnerability exists in the student management system by raisulislamg4 (up to commit 310d950e) that allows unauthenticated attackers to manipulate the role parameter in the user creation process. An attacker can submit malicious input through the add_user_check.php endpoint to execute arbitrary SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability has been publicly disclosed and proof-of-concept information is available, increasing the likelihood of active exploitation.

  • CVE-2026-10249HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Online Blood Bank Management System version 1.0 within the admin request-viewing interface. An unauthenticated attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to sensitive patient data, modification of records, or system disruption. Public exploits are already available, elevating the practical risk.

  • CVE-2026-10250HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Online Blood Bank Management System version 1.0 that allows unauthenticated attackers to manipulate the hospital parameter in the /admin/campsdetails.php file, potentially compromising the confidentiality, integrity, and availability of the system and its data. The vulnerability is remotely exploitable and public exploit code is available, elevating active exploitation risk.

  • CVE-2026-10251HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Online House Rental System version 1.0. An attacker can send a specially crafted request to the login functionality via the Username parameter to execute arbitrary database commands. Because the vulnerability requires no authentication and can be triggered remotely, it poses a significant risk to exposed instances. Public exploit code is available, increasing the likelihood of active exploitation.

  • CVE-2026-10252HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Online House Rental System version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the ID parameter in the /manage_tenant.php file. This could enable attackers to read, modify, or delete tenant data stored in the application's database without requiring any special credentials or user interaction. The vulnerability is publicly known and exploit code is available.

  • CVE-2026-10253HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Online House Rental System version 1.0. The vulnerability is located in the /manage_payment.php file, specifically in how it processes the ID parameter. An attacker can manipulate this parameter to inject malicious SQL commands, potentially allowing unauthorized access to sensitive payment and rental data. The vulnerability requires no authentication, can be exploited over the network, and exploit code is publicly available.

  • CVE-2026-10260HIGH 7.3

    CodeAstro Online Job Portal version 1.0 contains a SQL injection vulnerability in its admin job deletion function. An attacker can manipulate the ID parameter in the /admin/jobs-admins/delete-jobs.php file to inject malicious SQL commands, potentially compromising the database. The vulnerability requires no authentication and can be exploited over the network. Proof-of-concept code has been released publicly, increasing the likelihood of active exploitation.

  • CVE-2026-10261HIGH 7.3

    CodeAstro Online Job Portal version 1.0 contains a SQL injection vulnerability in its application status checking functionality. An attacker can manipulate the ID parameter in the /users/application_status.php file to inject malicious SQL commands, potentially gaining unauthorized access to the database. The vulnerability can be exploited remotely without authentication, making it accessible to anyone on the internet.

  • CVE-2026-10262HIGH 7.3

    A SQL injection vulnerability exists in Real State Services version 1.0 that allows an attacker to manipulate the Username parameter in the login form (/loginuser.php) to inject malicious SQL commands. Because no authentication is required and the vulnerability can be triggered over the network, an attacker can exploit this remotely to read, modify, or delete sensitive database information without needing valid credentials. The flaw has been publicly disclosed, increasing the risk of active exploitation.

  • CVE-2026-10263HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Computer Repair Shop Management System version 1.0 and earlier. An attacker can manipulate the ID parameter in the product management interface to inject malicious SQL commands, potentially exposing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the application.

  • CVE-2026-10290HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation System version 1.0, specifically in the tour.php file's GET parameter handler. An attacker can manipulate the 'tour' parameter to inject arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of the database. Because the vulnerability is remotely exploitable without authentication, and public exploits are available, organizations running this software face immediate risk.

  • CVE-2026-10606HIGH 7.3

    DedeCMS version 5.7.88 contains a SQL injection vulnerability in its feedback handling system. An attacker can manipulate user input passed to the TrimMsg function in the feedback component to inject malicious SQL commands. Since no authentication is required and the attack can be performed over the network, this vulnerability poses a significant risk to any organization running the affected version. The vulnerability has already been disclosed publicly, increasing the likelihood of active exploitation.

  • CVE-2026-10607HIGH 7.3

    DedeCMS 5.7.88 contains a SQL injection vulnerability in its friend links management function. An attacker can manipulate the 'msg' parameter in /plus/flink.php to inject malicious SQL commands, allowing unauthorized database access, modification, or deletion. No authentication is required, and the vulnerability can be exploited over the network. Public exploit code exists, elevating the practical risk.

  • CVE-2026-10608HIGH 7.3

    DedeCMS version 5.7.88 contains a SQL injection vulnerability in its RemoveXSS function within the /plus/carbuyaction.php file. An attacker can inject malicious SQL commands through the postname or des parameters without authentication, potentially compromising data confidentiality, integrity, and availability. The vulnerability is remotely exploitable and proof-of-concept code has been publicly released.

  • CVE-2026-10620HIGH 7.3

    A SQL injection vulnerability exists in code-projects Student Admission System version 1.0. The flaw resides in the /index.php file and can be exploited by manipulating the eid or did parameters. An attacker can inject malicious SQL commands without authentication, potentially reading or modifying sensitive student and admission data. Public exploit code is available, increasing the likelihood of active exploitation.

  • CVE-2026-10704HIGH 7.3

    SourceCodester's Pizzafy E-Commerce System version 1.0 contains a SQL injection vulnerability in the administrative login function. An attacker can manipulate the username field during authentication to inject malicious SQL commands, potentially gaining unauthorized database access without needing credentials or user interaction. The vulnerability is network-accessible and exploits are now publicly available.

  • CVE-2026-10877HIGH 7.3

    A SQL injection vulnerability exists in the SourceCodester Ship Ferry Ticket Reservation System version 1.0 and earlier. An attacker can exploit the admin login page by manipulating the Username parameter to execute arbitrary SQL commands remotely. No authentication is required to attempt the attack, and the vulnerability has already been publicly disclosed with functional exploits available.

  • CVE-2026-11334HIGH 7.3

    A SQL injection vulnerability exists in tittuvarghese CollegeManagementSystem that allows unauthenticated attackers to manipulate the department_code parameter in the dashboard form submission handler, leading to unauthorized database access and potential data theft or modification. The vulnerability is remotely exploitable without authentication, and public exploit information is already available. The affected software uses continuous delivery with rolling releases, making version tracking impractical.

  • CVE-2026-11342HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation System version 1.0. An attacker can manipulate the 'room' parameter in the /details.php file to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the affected application.

  • CVE-2026-11435HIGH 7.3

    Jinher OA 1.0 contains a SQL injection vulnerability in its nextselectplan.aspx file. An attacker can manipulate the httpOID parameter to inject malicious SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires no authentication and can be exploited over the network. Proof-of-concept code has been publicly disclosed.

  • CVE-2026-11450HIGH 7.3

    A command injection vulnerability exists in GL.iNet GL-MT3000 routers running firmware version 4.4.5 and earlier. An attacker can remotely exploit this flaw by manipulating the device name parameter in the HTTP RPC interface, allowing them to execute arbitrary commands on the affected device without authentication. The issue stems from insufficient input validation in the path normalization handler. GL.iNet has addressed this in firmware version 4.7 and later by implementing method-level validation that prevents the vulnerable eject_disk function from being called through the default RPC endpoint.

  • CVE-2026-11451HIGH 7.3

    GL.iNet's GL-MT3000 router firmware version 4.4.5 contains a command injection vulnerability in its FTP configuration handler. An attacker can remotely manipulate the media_dir parameter to inject and execute arbitrary shell commands without authentication. The vulnerability has been patched in firmware version 4.8.1, where the vendor implemented input escaping to neutralize quote-based command injection payloads.

  • CVE-2026-11452HIGH 7.3

    A command injection vulnerability exists in GL.iNet's GL-MT3000 router firmware versions up to 4.4.5. An attacker can remotely send a specially crafted password parameter to the SET_USER_PWD handler in the /cgi-bin/glc component, allowing arbitrary command execution on the device without authentication. The vulnerability stems from insufficient input validation when processing password input. GL.iNet has addressed this issue in firmware version 4.8.1 by properly escaping shell metacharacters and containing the password parameter within a safe execution context.

  • CVE-2026-11456HIGH 7.3

    Chanjet CRM 1.0 contains a SQL injection vulnerability in its HTTP GET request handler, specifically in the /tools/jxf_dump_systable.php file. An attacker can manipulate the gblOrgID parameter to inject malicious SQL commands, potentially allowing unauthorized access to or modification of database contents. The vulnerability requires no authentication and can be exploited over the network. Exploit code is publicly available, increasing the risk of active exploitation.

  • CVE-2026-11457HIGH 7.3

    A vulnerability has been discovered in JeeWMS, an open-source warehouse management system. The flaw exists in the JimuReport test-connection endpoint and allows attackers to manipulate database connection parameters (database type, driver, URL, username, and password) to inject malicious commands. An attacker on the network can exploit this without authentication to compromise the confidentiality, integrity, and availability of the system. Public exploit code is already available, increasing the practical risk.

  • CVE-2026-11471HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, affecting the password input field on the /index2.php page. An attacker can send a specially crafted login request over the network to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive database records. The attack requires no authentication and can be executed remotely. Public exploit code is available, increasing the risk of opportunistic exploitation.

  • CVE-2026-11472HIGH 7.3

    SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the Password parameter of /index1.php. An unauthenticated attacker can send specially crafted requests to the application to bypass authentication, extract database contents, or modify data. The vulnerability requires no user interaction and can be exploited over the network. Public exploit code exists, elevating risk significantly.

  • CVE-2026-11482HIGH 7.3

    A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can manipulate the 'sy' parameter in the /archive5.php file to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive database records. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-11483HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can send a specially crafted request to the /archive4.php endpoint that manipulates the 'sy' parameter to inject arbitrary SQL commands. Because no authentication is required and the vulnerability can be exploited over the network, a remote attacker can exploit this flaw to read, modify, or delete database records. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-11484HIGH 7.3

    A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /archive3.php file where an attacker can manipulate the 'sy' parameter to inject malicious SQL commands. Because no authentication is required and the attack can be carried out over the network, an unauthenticated attacker can exploit this to read, modify, or delete data from the underlying database. Public proof-of-concept code is now available, increasing the likelihood of real-world attacks.

  • CVE-2026-11485HIGH 7.3

    SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /archive2.php file. An attacker can manipulate the 'sy' parameter to inject malicious SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires no authentication and can be exploited remotely over the network. Public disclosure has occurred, increasing the likelihood of active exploitation.

  • CVE-2026-11486HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. The flaw is located in the /archive1.php file, where user input in the 'sy' parameter is not properly sanitized before being used in database queries. An attacker can exploit this remotely without authentication to read, modify, or delete database contents. Public exploit code is available, increasing the practical risk.

  • CVE-2026-11488HIGH 7.3

    A SQL injection vulnerability exists in Simple Flight Ticket Booking System version 1.0. The flaw resides in the checkUser.php file where user input in the Username parameter is not properly sanitized before being used in database queries. An attacker can exploit this remotely without authentication by submitting malicious SQL code through the POST request, potentially reading, modifying, or deleting database contents. Public disclosure of this vulnerability means active exploitation is a realistic concern.

  • CVE-2026-11489HIGH 7.3

    A SQL injection vulnerability exists in the Online Music Site application version 1.0, specifically in the album deletion administrative function. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially compromising the database. The vulnerability requires no authentication and can be exploited remotely, making it a significant risk for any instance of this application exposed to untrusted networks.

  • CVE-2026-11490HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Music Site version 1.0. The flaw is in the Search.php file where the Category parameter is not properly validated before being used in database queries. An attacker can send a specially crafted request over the network to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability requires no authentication and no user interaction, making it accessible to anyone on the internet. Public exploit code is available.

  • CVE-2026-11501HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System version 1.0. An attacker can manipulate the ID parameter in the patient-saving function to inject malicious SQL commands, potentially reading, modifying, or deleting patient records without authentication. The vulnerability is network-accessible and exploit code is publicly available, raising the risk of immediate abuse.

  • CVE-2026-11530HIGH 7.3

    A SQL injection vulnerability exists in the imvks786 student management system's login component. An attacker can manipulate the username and password parameters to inject malicious SQL commands, potentially gaining unauthorized access to the system or extracting sensitive student data. The vulnerability is remotely exploitable without authentication and does not require user interaction, making it a straightforward attack vector. Public exploit code is available, elevating the risk of active exploitation.

  • CVE-2026-11531HIGH 7.3

    A SQL injection vulnerability exists in the imvks786 student management system's administrator login endpoint. An attacker can manipulate username and password parameters to inject malicious SQL commands, potentially gaining unauthorized access or extracting sensitive data. The flaw affects the admin/admin_login.php file and can be exploited remotely without authentication. Public exploit code is available, increasing active threat likelihood.

  • CVE-2026-11582HIGH 7.3

    CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its web-based attendance interface. An attacker can manipulate the Username parameter in the /attendance-php/index.php file to inject malicious SQL commands, potentially allowing unauthorized access to student records, attendance data, or other sensitive information stored in the application's database. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the application.

  • CVE-2026-12775HIGH 7.3

    A SQL injection vulnerability exists in Montodel House-Rental-Management's login page. An attacker can manipulate the Username parameter in /login.php to inject malicious SQL commands, potentially reading, modifying, or deleting database contents without authentication. The vulnerability is remotely exploitable and requires no user interaction—an attacker can trigger it directly by sending a crafted request. Exploit code is publicly available, increasing the risk of active attacks.

  • CVE-2026-13485HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, accessible through the /preview.php file. An attacker can manipulate the course_year_section parameter to inject malicious SQL commands, potentially allowing unauthorized data access, modification, or deletion. The vulnerability requires no authentication or user interaction and can be exploited over the network. Public exploit information is available, increasing the practical risk.

  • CVE-2026-13486HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, specifically in the /preview6.php file. An attacker can manipulate the 'course_year_section' parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited from the internet. Public exploit code has been released, increasing the practical risk.

  • CVE-2026-13487HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can exploit a parameter in the /archive.php file to execute arbitrary SQL commands against the application's database. The vulnerability requires no authentication and can be triggered over the network, making it accessible to remote attackers. Exploit code is already publicly available, increasing the risk of active exploitation.

  • CVE-2026-13488HIGH 7.3

    A SQL injection vulnerability has been discovered in SourceCodester's Class and Exam Timetabling System version 1.0. The flaw exists in the /preview7.php file and can be exploited by manipulating the 'course_year_section' parameter. An attacker can send a specially crafted request over the internet to execute arbitrary SQL commands against the underlying database, potentially reading, modifying, or deleting sensitive data. The vulnerability requires no authentication or user interaction, and exploit code has already been released publicly, making active exploitation a genuine risk.

  • CVE-2026-13498HIGH 7.3

    A SQL injection vulnerability exists in the yashpokharna2555 restaurant management system, specifically in the password recovery feature. An attacker can manipulate the email parameter in POST requests to /forgotpassword.php to inject malicious SQL commands. Because the application fails to sanitize user input, an unauthenticated attacker on the internet can execute this attack without special privileges or user interaction, potentially gaining unauthorized access to sensitive database records.

  • CVE-2026-13500HIGH 7.3

    ANTLR4, a widely-used parser generator framework, contains a code injection vulnerability in how it processes grammar action blocks. An attacker can craft malicious input that manipulates the OutputFile handler to inject and execute arbitrary code during the code generation phase. This flaw requires no authentication and can be triggered remotely, making it a significant concern for anyone using ANTLR4 to build language tools, compilers, or domain-specific languages. The vulnerability affects versions up to and including 4.13.2.

  • CVE-2026-13521HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester's Class and Exam Timetabling System version 1.0, specifically in the /preview5.php file. An attacker can manipulate the 'course_year_section' parameter to inject malicious SQL commands without needing authentication. The vulnerability allows remote exploitation and poses a meaningful risk to confidentiality, integrity, and availability of affected systems. Exploit code is already publicly available.

  • CVE-2026-13526HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can inject malicious SQL commands through the ID parameter in the /edit_class.php file, allowing remote exploitation without authentication. This flaw enables attackers to read, modify, or delete database records. Public exploits are available, increasing the likelihood of active attacks.

  • CVE-2026-13527HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 that allows unauthenticated attackers to manipulate database queries through the course_year_section parameter in the /preview4.php file. The vulnerability can be exploited remotely without user interaction, potentially allowing attackers to read, modify, or delete sensitive academic data. Public disclosure of this vulnerability means that attack code is already available, increasing the risk of active exploitation.

  • CVE-2026-13550HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Baptism Information Management System version 1.0. An attacker can send a specially crafted request to the /delbaptism.php file that manipulates the ID parameter to inject malicious SQL commands. This could allow unauthorized access to, modification of, or deletion of data in the underlying database. The vulnerability requires no authentication and can be exploited from the internet by an unauthenticated attacker. Public exploit code has been released, increasing the risk of active attacks.

  • CVE-2026-13551HIGH 7.3

    itsourcecode's Baptism Information Management System version 1.0 contains a SQL injection vulnerability in its editBaptism.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited remotely, making it a practical concern for organizations running this software. Public exploit disclosure means this risk is elevated in the current threat landscape.

  • CVE-2026-13552HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Online Hotel Management System version 1.0 that allows unauthenticated remote attackers to manipulate database queries through the amenities management interface. By tampering with the amen_id parameter in the admin panel, an attacker can execute arbitrary SQL commands without requiring valid credentials or user interaction. The vulnerability has been publicly disclosed and exploit code is available, increasing the practical risk.

  • CVE-2026-13555HIGH 7.3

    itsourcecode Online Hotel Management System version 1.0 contains a SQL injection vulnerability in its admin user management interface. An unauthenticated attacker can send a crafted request to the /admin/mod_users/controller.php endpoint with malicious input in the Name parameter, allowing them to execute arbitrary SQL queries against the backend database. This could lead to unauthorized data access, modification, or deletion. Public exploit code exists for this vulnerability, increasing the immediate risk.

  • CVE-2026-13559HIGH 7.3

    A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the single-list_sale.php file. An unauthenticated attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. The vulnerability is remotely exploitable and public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-13565HIGH 7.3

    SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_class1.php endpoint. An unauthenticated attacker can manipulate the ID parameter to inject arbitrary SQL commands, potentially reading, modifying, or deleting database records. The vulnerability is remotely exploitable without authentication and has been publicly disclosed, meaning attack code may be in active circulation.

  • CVE-2026-13566HIGH 7.3

    A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /preview3.php file, where user-supplied input in the course_year_section parameter is not properly sanitized before being used in database queries. An attacker can send a specially crafted request to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive academic data. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14640HIGH 7.3

    CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its login functionality. An attacker can manipulate the Username parameter on the /index.php login page to inject malicious SQL commands, bypassing authentication and potentially accessing sensitive data. The vulnerability requires no authentication or user interaction to exploit and can be executed remotely over the network. Public exploit code is available, increasing the immediate risk to deployed systems.

  • CVE-2026-14641HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, accessible through the /edit_course.php endpoint. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially extracting, modifying, or deleting database records. No authentication is required, and the vulnerability can be exploited over the network. Public disclosure means threat actors have ready-made exploitation techniques available.

  • CVE-2026-14642HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 in the /edit_class2.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to or modification of the database. The vulnerability requires no authentication and can be exploited remotely. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14648HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Voting System affecting versions up to 0.x/1.0. The flaw resides in the login authentication component, specifically in how the system processes the adminUserName and adminPassword parameters. An attacker can bypass authentication and manipulate the underlying database by injecting malicious SQL commands through these input fields. Because the vulnerability allows unauthenticated remote exploitation and the exploit code is publicly available, it poses an immediate threat to any organization running this voting system.

  • CVE-2026-14649HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Voting System version 1.0. The vulnerability affects the voting submission functionality, specifically the `/saveVote.php` file's `test_input` function. An attacker can manipulate voter-related fields (voterName, voterEmail, voterID, or selectedCandidate) to inject malicious SQL commands. Because the vulnerability requires no authentication and can be triggered remotely over the network, an attacker can exploit it without prior system access or user interaction.

  • CVE-2026-14652HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the username field on the admin login page. This could enable attackers to bypass authentication, extract sensitive data, modify database contents, or cause system disruption. The vulnerability is network-accessible and requires no user interaction or authentication to exploit, making it immediately actionable for threat actors. Public exploit information is available, increasing real-world attack probability.

  • CVE-2026-14653HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. The vulnerability is located in the admin panel at /admin/mensproductdeletequery.php and can be exploited by manipulating the user_id parameter. An attacker can send a specially crafted request over the network without authentication to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. Public exploit code is available, elevating the immediate risk.

  • CVE-2026-14654HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. An attacker can manipulate the user_id parameter in the /admin/girlsproductdeletequery.php file to inject malicious SQL commands. Because this admin endpoint requires no authentication and can be accessed over the network, an unauthenticated remote attacker can exploit this flaw to read, modify, or delete database contents. Public exploits are already available, increasing the practical risk.

  • CVE-2026-14660HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Job Portal version 1.0 that allows unauthenticated attackers to manipulate login credentials and execute arbitrary SQL queries. The vulnerability is in the login.php file, specifically in how it processes the txtUser and txtPass parameters. An attacker can craft malicious input to bypass authentication, extract sensitive data, or modify the database. Public exploit information is available, increasing the risk of active exploitation.

  • CVE-2026-14688HIGH 7.3

    itsourcecode Online Hotel Management System version 1.0 contains a SQL injection vulnerability in its admin login functionality. An attacker can exploit a flaw in how the system processes the email parameter to inject malicious SQL commands without authentication, potentially exposing or modifying sensitive data in the underlying database. The vulnerability is network-accessible and proof-of-concept exploits are publicly available.

  • CVE-2026-14695HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Multi-Vendor Online Grocery Management System version 1.0, specifically in the user registration function. An attacker can send a malicious request with a specially crafted name field to bypass input validation and execute arbitrary SQL commands against the backend database. No authentication is required, and the vulnerability can be exploited over the network. Public proof-of-concept code has been released, making this an active threat.

  • CVE-2026-14700HIGH 7.3

    A SQL injection vulnerability exists in the Employer Login Endpoint of code-projects Internship Management System version 1.0. An attacker can inject malicious SQL commands through the email or password login fields without authentication, potentially accessing, modifying, or deleting sensitive data in the application's database. The vulnerability is accessible over the network and has been publicly disclosed, making active exploitation more likely.

  • CVE-2026-14705HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Examination version 1.0 that allows unauthenticated attackers to manipulate user credentials (uname/password parameters) passed to the head.php file, potentially extracting sensitive data, modifying records, or disrupting service availability. The vulnerability is network-accessible, requires no user interaction, and has been publicly disclosed with exploitation details available.

  • CVE-2026-14713HIGH 7.3

    SourceCodester Pizzafy E-Commerce System version 1.0 contains a SQL injection vulnerability in its admin panel. An attacker can manipulate the ID parameter in the /admin/ajax.php?action=confirm_order endpoint to execute arbitrary SQL commands without authentication. Because the vulnerability is remotely exploitable and requires no user interaction, it poses a significant risk to affected systems. Public exploit code is available, increasing the likelihood of active attacks.

  • CVE-2026-14722HIGH 7.3

    TidGi-Desktop, a desktop application for managing TiddlyWiki repositories, contains a code injection vulnerability affecting versions up to 0.13.0. An attacker can exploit this flaw remotely without authentication to inject and execute arbitrary code. Because exploit code has already been published, the risk of active attacks is elevated. The vulnerability exists in the Git Repository Import functionality, which processes wiki tiddlers from external sources.

  • CVE-2026-14732HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 affecting the /edit_exam.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the practical risk.

  • CVE-2026-14733HIGH 7.3

    SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_coursea.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially gaining unauthorized access to or modifying the underlying database. This vulnerability requires no authentication and can be exploited remotely over the network. Public exploits are currently available.

  • CVE-2026-14734HIGH 7.3

    A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /edit_product.php file where user-supplied input in the ID parameter is not properly validated before being used in database queries. An attacker can exploit this remotely without authentication to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive data. Public exploit code is available, elevating the practical risk.

  • CVE-2026-14735HIGH 7.3

    A SQL injection vulnerability exists in code-projects Smart Parking System version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the street, city, or status parameters in the /parkings/parkings.php file. An attacker can exploit this remotely without any user interaction to read, modify, or delete database contents. The vulnerability has been publicly disclosed, increasing the immediate risk of active exploitation.