By weakness (CWE)

CWE-74: related vulnerabilities

CVEs classified under CWE-74. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

264 published vulnerabilities · page 2 of 3

  • CVE-2026-14737HIGH 7.3

    A SQL injection flaw exists in Hanwang e-Face General Management Platform version 6.3.5.4 affecting the /sysAuthStr/querySysAuthStr.do endpoint. By manipulating the order of function arguments, an attacker can inject malicious SQL commands without authentication. The vulnerability can be exploited remotely and proof-of-concept code is publicly available, raising the risk of active exploitation.

  • CVE-2026-14743HIGH 7.3

    A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the /normalHomeSale.php file. An attacker can manipulate the 'loc' parameter to inject malicious SQL commands, potentially gaining unauthorized access to the database. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the affected application. A public exploit is already available, increasing the practical risk.

  • CVE-2026-14744HIGH 7.3

    A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the /normalHomeRental.php file. The flaw allows attackers to manipulate the 'loc' parameter to execute arbitrary SQL commands against the application's database. Since this vulnerability can be triggered remotely without authentication, and exploit code has been publicly released, organizations using this software face active exploitation risk.

  • CVE-2026-14745HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows unauthenticated attackers to manipulate the ID parameter in the /single-list_rent.php file, potentially exposing or altering sensitive data in the underlying database. The vulnerability can be exploited remotely without authentication, and proof-of-concept code is publicly available, increasing the risk of active exploitation.

  • CVE-2026-14746HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows unauthenticated remote attackers to manipulate the 'amen' parameter in the /addprojectrent.php file to execute arbitrary SQL queries. The vulnerability has been publicly disclosed and exploitation code is available, increasing the risk of active exploitation. Any organization running this real estate management application should treat this as a high-priority security issue requiring immediate patching or mitigation.

  • CVE-2026-14747HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows an unauthenticated attacker to inject malicious SQL commands through the 'amen' parameter in the /addprojectsale.php file. Because no authentication is required and the vulnerability can be exploited over the network, an attacker could potentially read, modify, or delete database records without legitimate access. This is a remotely exploitable flaw affecting a real estate management application.

  • CVE-2026-14749HIGH 7.3

    A code injection vulnerability exists in mjperpinosa stumasy that allows remote attackers to execute arbitrary code through a parameter in the calculator application. An attacker can send a specially crafted mathematical expression to the eval function without authentication, potentially compromising the affected system. The vulnerability has been publicly disclosed and working exploits are available, raising the urgency of remediation.

  • CVE-2026-14750HIGH 7.3

    A SQL injection vulnerability has been identified in mjperpinosa stumasy, a project using continuous rolling releases. An attacker can manipulate the Password parameter in the Notes controller's dictionary authorization function to inject malicious SQL commands, potentially compromising database integrity and extracting sensitive information. The flaw is remotely exploitable without requiring authentication, and proof-of-concept code has already been released publicly, increasing the risk of active exploitation.

  • CVE-2026-14754HIGH 7.3

    A SQL injection vulnerability exists in Hotel and Tourism Reservation version 1.0, specifically in the admin room management interface. An unauthenticated attacker can manipulate several input parameters—including room description, price, type, number, and image deletion fields—to execute arbitrary SQL commands against the backend database. The vulnerability requires no user interaction and can be exploited remotely, making it a direct network-based attack surface.

  • CVE-2026-14755HIGH 7.3

    A SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation system version 1.0. The flaw is located in the reservations management page at /admin/reservations.php, where user input passed through the 'delete' parameter is not properly validated before being used in database queries. An unauthenticated attacker on the network can exploit this remotely to read, modify, or delete sensitive reservation data and potentially gain deeper access to the system. Public disclosure means defensive awareness is urgent.

  • CVE-2026-14756HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation system (version 1.0) that allows unauthenticated attackers to manipulate database queries through the tour deletion function. An attacker can send a specially crafted request to the `/admin/add_tour.php` page targeting the `delete_image` parameter to execute arbitrary SQL commands, potentially accessing, modifying, or deleting sensitive reservation and customer data. The vulnerability requires no special privileges or user interaction, making it straightforward to exploit over the network. Public exploit information is already available, elevating the urgency of patching.

  • CVE-2026-14762HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation system version 1.0, specifically in the room management administrative interface. An attacker can manipulate the 'delete' parameter in the /admin/rooms.php file to execute unauthorized database queries without authentication. This allows remote attackers to read, modify, or delete sensitive data from the reservation system's database. The vulnerability is now public and active exploits are known to exist.

  • CVE-2026-14763HIGH 7.3

    A SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the tour parameter in the administrative tour reservations page. An attacker can exploit this remotely without special privileges or user interaction, potentially compromising sensitive reservation and customer data stored in the application database.

  • CVE-2026-14764HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation system version 1.0, specifically in the event management administrative interface. An attacker can inject malicious SQL commands through the event details parameter to manipulate database queries without requiring authentication. This allows unauthorized access to, modification of, or deletion of sensitive data stored in the application database.

  • CVE-2026-14768HIGH 7.3

    A SQL injection vulnerability has been discovered in code-projects Real State Services version 1.0 affecting the /builderHome.php file. An attacker can inject malicious SQL commands through the 'loc' parameter without authentication, potentially reading, modifying, or deleting database records. Public exploit code is available, making this a practical threat that requires immediate patching.

  • CVE-2026-14769HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 affecting the /pay.php file. An unauthenticated attacker can inject malicious SQL code through the Bankname parameter to manipulate database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is remotely exploitable without any user interaction, and proof-of-concept code has been publicly disclosed, increasing immediate risk.

  • CVE-2026-14770HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 that allows unauthenticated remote attackers to manipulate the ID parameter in the /edit_room.php file to execute arbitrary database queries. The vulnerability requires no user interaction and can be exploited from the network without authentication, making it a significant remote code execution risk for organizations running this scheduling software.

  • CVE-2026-14771HIGH 7.3

    SourceCodester's Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_exam1.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, allowing them to read, modify, or delete database contents without authentication. Because this vulnerability requires no user interaction and can be exploited over the network, it represents a significant risk to organizations running this application.

  • CVE-2026-14772HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 affecting the /edit_course1.php file. An attacker can manipulate the ID parameter to inject arbitrary SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires no authentication and can be exploited over the network. Public disclosure has occurred, increasing exploitation risk.

  • CVE-2026-15134HIGH 7.3

    CodeAstro Simple Online Leave Management System version 1.0 contains a SQL injection vulnerability in its index.php file. An attacker can manipulate the email parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data without authentication. The vulnerability is network-accessible and exploit code has already been made public, increasing the risk of active exploitation.

  • CVE-2026-15135HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Food Order System version 1.0, specifically in the /edit_food_items.php file. An attacker can manipulate the 'update' parameter to inject arbitrary SQL commands without authentication. This allows remote code execution and data manipulation. Public exploits are available, increasing immediate risk.

  • CVE-2026-15137HIGH 7.3

    A SQL injection vulnerability has been discovered in code-projects Interview Management System version 1.0. An attacker can manipulate the ID parameter in the application to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive data in the backend database. The vulnerability requires no authentication and can be triggered from the network without user interaction. Public exploit code is available, elevating the risk of active exploitation.

  • CVE-2026-15190HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. An attacker can manipulate the Username parameter in the login page (/login.php) to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data without authentication. The vulnerability is network-accessible and requires no user interaction, making it straightforward to exploit. Public exploit code is now available.

  • CVE-2026-47634HIGH 7.3

    A vulnerability in Microsoft Office SharePoint allows someone with valid access to inject malicious content that tricks downstream components into displaying fake or spoofed information to other users. The attacker must have legitimate credentials and convince a user to interact with the malicious content, but once triggered, the attack succeeds reliably and can achieve high impact by either stealing sensitive data or modifying what users see.

  • CVE-2025-27511HIGH 7.2

    GeoServer, a widely-used open-source geospatial data platform, contains a vulnerability in its DB2 DataStore Extension that allows authenticated administrators to execute arbitrary code on the server through a malicious database connection string. An attacker with admin credentials can craft a specially crafted DB2 JDBC URL that exploits JNDI (Java Naming and Directory Interface) injection to achieve remote code execution. The vulnerability was patched in version 2.27.0.

  • CVE-2026-12197HIGH 7.2

    A command injection vulnerability exists in Ruijie EG105G-P version 2.340, specifically in the network diagnostic endpoint accessible via the web interface. An authenticated attacker can manipulate the target parameter of the nslookup function to inject and execute arbitrary system commands on the affected device. The vulnerability is remotely exploitable and public exploit code has been released. The vendor has not responded to early disclosure efforts.

  • CVE-2026-58213HIGH 7.1

    NATS Server, a widely-used message broker for cloud and edge infrastructure, contains a protocol injection vulnerability in its MQTT connector. An authenticated MQTT client can embed special control characters in subscription filters that get forwarded unchanged into the NATS protocol stream sent to other servers in the cluster or leafnode connections. This corrupts the protocol state and allows an attacker to inject arbitrary NATS commands, potentially reading or manipulating messages intended for other applications. The flaw requires an authenticated MQTT connection but no special network access, making it a meaningful risk for deployments with untrusted or compromised MQTT clients.

  • CVE-2026-47644MEDIUM 6.5

    A flaw in Microsoft Edge's Copilot Chat feature allows attackers to inject specially crafted code into the application, potentially exposing sensitive information. The vulnerability requires user interaction (such as clicking a malicious link) but does not require authentication. Once triggered, it could disclose data over the network without the user's knowledge.

  • CVE-2026-49097MEDIUM 6.5

    Apache Camel's IRC component contains a flaw that allows attackers to redirect IRC messages to unintended recipients through HTTP requests. When a web application uses Camel to bridge HTTP traffic into IRC channels, an attacker can inject special HTTP headers that override the intended destination, causing messages to be diverted to attacker-controlled IRC channels or users. This leak can expose sensitive message content or make automated bots appear to send malicious messages on an attacker's behalf. The vulnerability requires an unauthenticated HTTP consumer to function but does not require credentials or specialized attack tools.

  • CVE-2026-8993MEDIUM 6.5

    The D.Launcher 2 component in the Slovak eID client ecosystem improperly handles custom URL protocols, allowing attackers to trigger NTLM authentication attempts or SMB connections to their servers, or conduct Server-Side Request Forgery (SSRF) attacks. The vulnerability requires a user to click a malicious link, making it a social engineering vector rather than an automated remote code execution. The exposure is primarily information disclosure through credential capture or network reconnaissance.

  • CVE-2026-10060MEDIUM 6.3

    TRENDnet's TEW-432BRP wireless router (firmware version 3.10B20) contains a command injection vulnerability in its route configuration interface. An authenticated attacker can manipulate IP, mask, or gateway parameters to inject arbitrary commands on the device. The vulnerability requires valid credentials but poses a direct threat to affected networks. Critically, this product reached end-of-life in 2009—over 15 years ago—and the vendor has stated it cannot replicate or fix vulnerabilities in legacy hardware.

  • CVE-2026-10061MEDIUM 6.3

    A command injection vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20), discovered in the WPS configuration function. An authenticated attacker can manipulate the peerPin parameter to execute arbitrary commands on the device. The vulnerability is network-accessible and requires valid login credentials. Notably, this router reached end-of-life in 2009—over 15 years ago—and TRENDnet has stated they cannot replicate or provide fixes for vulnerabilities in this legacy hardware. While exploit code is public, the practical risk is limited to organizations still operating this obsolete equipment in production environments.

  • CVE-2026-10127MEDIUM 6.3

    A command injection vulnerability exists in Edimax BR-6478AC wireless routers running firmware version 1.23. An authenticated attacker can send a specially crafted web request to the device's configuration interface that tricks it into executing arbitrary system commands. The vulnerability stems from improper validation of the 'rootAPmac' parameter in the device's wireless driver setup function. Because proof-of-concept code has been publicly released, there is a meaningful risk that attackers will attempt to exploit this flaw in active environments.

  • CVE-2026-10166MEDIUM 6.3

    A command injection vulnerability exists in Edimax BR-6478AC version 1.23 that allows an authenticated attacker to execute arbitrary commands on the device. The flaw is in the web interface's wireless settings handler, where the rootAPmac parameter is not properly sanitized before being used in system commands. An attacker with valid login credentials can manipulate this parameter to inject malicious commands, potentially compromising router configuration, data, or availability. Public exploit details are available, increasing real-world risk.

  • CVE-2026-10170MEDIUM 6.3

    A SQL injection vulnerability exists in code-projects Visitor Management System version 1.0. An authenticated attacker can manipulate the 'phone' parameter in the /vms/php/phone_0.php file to inject malicious SQL commands. This allows the attacker to read, modify, or delete database contents without special privileges. The vulnerability requires valid login credentials to exploit and has a published proof-of-concept.

  • CVE-2026-10175MEDIUM 6.3

    A code injection vulnerability exists in Aider-AI Aider version 0.86.3 within the Architect Mode feature. An authenticated user can manipulate the editor_coder.run function in auth.py to inject and execute arbitrary code on the system. The flaw requires valid credentials to exploit but no additional user interaction, making it a direct threat to organizations using this development assistance tool. Public exploit code is already available.

  • CVE-2026-10176MEDIUM 6.3

    Aider-AI's Aider version 0.86.3 contains a SQL injection vulnerability in its code generation workflow that can be exploited by authenticated users to manipulate database queries. While the vulnerability requires login credentials to trigger, an attacker with access can extract, modify, or delete sensitive data. Public exploit information is available, increasing the near-term risk of active exploitation.

  • CVE-2026-10180MEDIUM 6.3

    A command injection vulnerability exists in the TRENDnet TEW-432BRP router (firmware version 3.10B20) that allows authenticated users to execute arbitrary system commands through the formSysCmd web interface parameter. The vulnerability is in the /goform/formSysCmd endpoint and can be exploited remotely by anyone with network access and valid credentials. TRENDnet has not patched this issue because the router reached end-of-life in 2009 and is no longer supported.

  • CVE-2026-10182MEDIUM 6.3

    A remote command injection vulnerability exists in the TRENDnet TEW-432BRP wireless router running firmware version 3.10B20. An authenticated attacker can exploit the WLAN setup function by manipulating the 'enrollee' parameter to execute arbitrary commands on the device. The vulnerability has been publicly disclosed. However, this router reached end-of-life in 2009—over 15 years ago—and the vendor has stated they cannot replicate or fix vulnerabilities in products no longer supported. Organizations still operating this hardware face unpatched exposure.

  • CVE-2026-10193MEDIUM 6.3

    OFCMS versions up to 1.1.3 contain a SQL injection vulnerability in the ComnController component. An authenticated attacker can manipulate the 'system.user.query' parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting database records. The vulnerability has been publicly disclosed and exploit code is available, making active exploitation a realistic threat.

  • CVE-2026-10202MEDIUM 6.3

    A SQL injection vulnerability exists in OFCMS version 1.1.3 affecting the JSON Query Interface within the SystemDictController component. An authenticated attacker can send specially crafted queries to manipulate SQL commands executed by the application, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials but can be exploited over the network without user interaction. Exploit code is publicly available, increasing the risk of active exploitation.

  • CVE-2026-10203MEDIUM 6.3

    A SQL injection vulnerability exists in OFCMS 1.1.3 within the Query function of the SystemParamController component. The flaw allows authenticated attackers to inject malicious SQL commands through the JSON Query Interface, potentially compromising database integrity and confidentiality. Public exploit code is available, increasing active exploitation risk.

  • CVE-2026-10204MEDIUM 6.3

    A SQL injection vulnerability has been discovered in OFCMS version 1.1.3, specifically in the JSON Query Interface of the user management controller. An authenticated attacker can submit specially crafted queries to execute arbitrary SQL commands against the application's database. This could allow them to read, modify, or delete sensitive data. The vulnerability is not currently on the CISA Known Exploited Vulnerabilities (KEV) catalog, but exploit code has been publicly released, increasing the practical risk of attacks.

  • CVE-2026-10209MEDIUM 6.3

    A SQL injection vulnerability exists in the Online Hospital Management System version 1.0, specifically in the appointment booking functionality. An authenticated attacker can manipulate the 'editid' parameter in the appointmentdetail.php file to inject malicious SQL commands. This allows an attacker with valid credentials to read, modify, or delete sensitive appointment and patient data without additional authorization. Since the exploit has been publicly disclosed, the risk of active exploitation is elevated.

  • CVE-2026-10210MEDIUM 6.3

    AstrBot version 4.23.6 contains a vulnerability in its skill management system that allows authenticated users to inject malicious code through the prompt description field. An attacker with login credentials can manipulate how skill prompts are processed, potentially leading to unauthorized data access, system modification, or service disruption. The vulnerability has been publicly disclosed, and exploit code is available, though the vendor has not engaged with disclosure efforts.

  • CVE-2026-10223MEDIUM 6.3

    NousResearch's hermes-agent software contains an injection vulnerability in its memory scanning tool that allows authenticated users to inject malicious input. An attacker with valid credentials can exploit this flaw remotely to manipulate the application's memory handling logic. The vulnerability affects all versions up to 2026.4.30, and exploit code has already been publicly disclosed, raising the practical risk despite a moderate CVSS score.

  • CVE-2026-10235MEDIUM 6.3

    CodeAstro Ingredients Stock Management System version 1.0 contains a SQL injection vulnerability in its stock manager component. An authenticated attacker can manipulate the txt_search_category parameter in the /Ingredients-Stock/stock_manager.php file to execute arbitrary SQL queries. This allows unauthorized data access, modification, or deletion within the application's database. The vulnerability requires valid login credentials but can be exploited over the network without user interaction.

  • CVE-2026-10242MEDIUM 6.3

    itsourcecode Content Management System version 1.0 contains a SQL injection vulnerability in the /instructions.php file. An attacker with user-level access can manipulate the topic_id parameter to execute unauthorized database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is remotely exploitable and public exploit code is available.

  • CVE-2026-10256MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Content Management System version 1.0 affecting the comment-saving functionality. An authenticated attacker can manipulate the Name parameter in /save_comment.php to execute arbitrary SQL queries, potentially reading, modifying, or deleting database contents. The vulnerability requires valid user credentials but does not require user interaction to exploit. Public exploit code is available, elevating the practical risk despite the MEDIUM CVSS score.

  • CVE-2026-10257MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Content Management System version 1.0, specifically in the admin update functionality. An authenticated user can inject malicious SQL commands through the topic_id parameter when uploading images, potentially reading, modifying, or deleting database contents. Public exploit code is available, increasing near-term risk.

  • CVE-2026-10258MEDIUM 6.3

    itsourcecode Content Management System version 1.0 contains a SQL injection vulnerability in its administrative interface. An authenticated attacker can manipulate the topic_id parameter in the /admin/add_sub_topic.php file to inject malicious SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. The vulnerability requires valid login credentials but can be exploited over the network without additional user interaction.

  • CVE-2026-10265MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Content Management System version 1.0 that allows authenticated users to manipulate the topic_id parameter in the /admin/edit_topic.php file to execute arbitrary SQL queries. An attacker with valid admin credentials can exploit this to read, modify, or delete database records. Public exploits are available, elevating operational risk.

  • CVE-2026-10286MEDIUM 6.3

    CodeAstro Payroll System version 1.0 contains a SQL injection vulnerability in its employee home page functionality. An authenticated attacker can inject malicious SQL commands through the emp_id parameter, allowing them to read, modify, or delete database records. This vulnerability requires valid login credentials and is reachable over the network. Public exploit information is available, increasing the immediate risk of exploitation.

  • CVE-2026-10296MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 that allows authenticated users to manipulate the Username parameter in the /ajax.php endpoint to execute arbitrary SQL queries. An attacker with valid login credentials can exploit this flaw to read, modify, or delete database contents. The vulnerability requires authentication but is otherwise straightforward to exploit and has been publicly disclosed.

  • CVE-2026-10297MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 within the course management functionality. An authenticated attacker can manipulate the ID parameter in the /manage_course.php endpoint to execute arbitrary SQL queries against the underlying database. The vulnerability requires valid login credentials but can be exploited over the network without additional interaction. Exploit code is publicly available, elevating the practical risk.

  • CVE-2026-10302MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 within the /manage_fee.php file. An authenticated attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. The vulnerability requires valid user credentials to exploit but can be triggered remotely over the network.

  • CVE-2026-10550MEDIUM 6.3

    A command injection vulnerability exists in elunez eladmin versions up to 2.7 within the Application Deployment Module. An authenticated user can manipulate the uploadPath argument to inject arbitrary commands, leading to remote code execution on the affected system. The vulnerability requires valid credentials to exploit but does not need user interaction once authenticated. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-10568MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the /manage_payment.php file to execute arbitrary SQL queries against the backend database. This vulnerability requires valid login credentials to exploit, but can lead to unauthorized data access, modification, or deletion. Public exploit code is available, increasing the practical risk of exploitation.

  • CVE-2026-10808MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 that allows authenticated users to manipulate the ID parameter in the /manage_student.php file, potentially enabling unauthorized data access, modification, or deletion. The vulnerability requires valid login credentials but can be exploited remotely over the network. Public exploit code is available, elevating the risk of active attack.

  • CVE-2026-10809MEDIUM 6.3

    CVE-2026-10809 is a SQL injection vulnerability in itsourcecode Fees Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the /manage_user.php file to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The flaw requires valid login credentials but can be exploited over the network without user interaction. Public exploit code is available, elevating the practical risk despite the medium CVSS score.

  • CVE-2026-10811MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0. The flaw resides in the /receipt.php file, specifically in how the application processes the ef_id parameter. An authenticated attacker can manipulate this parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete database records. Public disclosure of this vulnerability means exploitation techniques are already available, elevating the practical risk.

  • CVE-2026-10874MEDIUM 6.3

    A SQL injection vulnerability exists in projectworlds Online Art Gallery Shop Project version 1.0 affecting the admin dashboard. An authenticated attacker can manipulate the 'social_insta' parameter in the /admin/adminHome.php file to inject malicious SQL commands. This allows unauthorized access to sensitive database information, modification of data, or potential system disruption. The vulnerability requires valid login credentials but has no other technical barriers to exploitation.

  • CVE-2026-10875MEDIUM 6.3

    A SQL injection vulnerability exists in projectworlds Online Art Gallery Shop Project version 1.0 that allows authenticated users to inject malicious SQL commands through the social_twitter parameter in the admin panel. An attacker with login credentials can exploit this flaw to read, modify, or delete database records. Public exploit code has been released, increasing the risk of active exploitation.

  • CVE-2026-10878MEDIUM 6.3

    A command injection vulnerability has been discovered in D-Link DWR-M920 routers running firmware versions 1.1.50 and 1.1.70. An authenticated attacker can manipulate a parameter in the SMS management interface to inject and execute arbitrary system commands. This requires an existing login to the device but does not require user interaction once authenticated. Public exploits are now available, increasing the practical risk.

  • CVE-2026-11339MEDIUM 6.3

    A command injection vulnerability exists in D-Link DWR-M920 routers up to firmware version 1.1.50. An authenticated attacker can inject arbitrary commands through the USSD Setup function, potentially gaining remote code execution on the device. The vulnerability requires valid login credentials but does not need user interaction to exploit. Public exploit code is now available.

  • CVE-2026-11406MEDIUM 6.3

    GL.iNet MT3000 routers running firmware versions up to 4.4.5 contain a command injection flaw in the OpenVPN client import process. An authenticated user can craft a malicious OpenVPN configuration file that, when imported through the web interface, executes arbitrary system commands with the privileges of the router's web service. The vendor has released patched firmware that validates OpenVPN configuration files to block injection attempts.

  • CVE-2026-11412MEDIUM 6.3

    Jinher OA C6 contains a SQL injection vulnerability in a web component that processes form identifiers. An attacker with login credentials can manipulate the queryID parameter in GetFormSyn.aspx to execute arbitrary database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is network-accessible and exploit code has been publicly released, increasing the risk of active exploitation.

  • CVE-2026-11447MEDIUM 6.3

    A command injection vulnerability exists in GL.iNet's GL-MT3000 router firmware versions up to 4.4.5. The flaw is located in the MTK Backend component (iwinfo.so) and can be exploited by an authenticated remote attacker to inject arbitrary commands through the device parameter. This allows an attacker with valid credentials to execute unauthorized system commands. The vendor has released version 4.7 with global protections to intercept malicious injection attempts.

  • CVE-2026-11449MEDIUM 6.3

    GL.iNet has patched a command injection vulnerability affecting their GL-MT3000 router running firmware 4.4.5. An authenticated attacker could execute arbitrary commands through the LuCI JSON-RPC interface, potentially compromising the router and devices on its network. The vulnerability is addressed in firmware 4.8.1 and later, though newer versions (4.7.13+) mitigate it by excluding LuCI by default.

  • CVE-2026-11453MEDIUM 6.3

    Tiobon Employee Self-Service System versions up to 7.2 contain a SQL injection flaw in the blog search functionality accessible through the login endpoint. An authenticated attacker can manipulate search keywords to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials and has been publicly disclosed, though it is not currently tracked in the CISA Known Exploited Vulnerabilities catalog. The vendor has not acknowledged or addressed this issue despite early notification.

  • CVE-2026-11473MEDIUM 6.3

    A SQL injection vulnerability exists in jflyfox jfinal_cms versions up to 5.1.0 that allows authenticated users to manipulate the orderBy parameter in the AdvicefeedbackController, potentially exposing or modifying database contents. The vulnerability requires valid login credentials but can be exploited over the network without user interaction once authenticated.

  • CVE-2026-11475MEDIUM 6.3

    A SQL injection vulnerability has been discovered in Kushan2k's student-management-system affecting the Certificate Verification Endpoint. An attacker with login credentials can manipulate the 'nic' parameter in the getStatus function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability is rated MEDIUM severity and exploits have been publicly disclosed, creating immediate risk for deployed instances.

  • CVE-2026-11480MEDIUM 6.3

    A SQL injection vulnerability exists in BeikeShop, an e-commerce platform by Chengdu Everbrite Network Technology, affecting versions up to 1.6.0.22. An authenticated attacker can manipulate the 'settings.value' parameter in the Admin Design Builder endpoint to inject malicious SQL commands. The vulnerability requires login credentials but carries a network-based attack vector, allowing an attacker with admin or user-level access to read, modify, or delete database contents.

  • CVE-2026-11495MEDIUM 6.3

    CodeAstro Ingredients Stock Management System version 1.0 contains a SQL injection vulnerability in its stock addition functionality. An authenticated attacker can manipulate the ID parameter in the /Ingredients-Stock/add_stock.php file to execute arbitrary SQL queries. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid credentials to exploit but carries moderate severity due to its potential for data theft and integrity compromise.

  • CVE-2026-11506MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff deletion search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_for_deletion.php file to inject malicious SQL commands. This could allow unauthorized access to sensitive database information, modification of records, or disruption of the system. The vulnerability requires an authenticated login but poses a meaningful risk in environments where user accounts are shared or weak credential hygiene exists.

  • CVE-2026-11507MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Leave Management System version 1.0 that allows authenticated users to manipulate the leave_type parameter in the admin delete function, potentially extracting or modifying database information. The flaw requires valid login credentials but no additional user interaction, and public exploit code is available.

  • CVE-2026-11508MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff assignment search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_to_assign_pc.php file to inject malicious SQL commands. This allows remote exploitation without user interaction and poses a direct risk to database confidentiality, integrity, and availability. Public disclosure of this vulnerability means active exploitation is possible.

  • CVE-2026-11509MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff search functionality. An authenticated user can manipulate the Name parameter in the /admin/search_staff_for_updation.php file to inject arbitrary SQL commands, potentially reading or modifying sensitive employee and leave data. The vulnerability requires valid login credentials but poses a meaningful risk to organizations using this system, as it could enable unauthorized data access or manipulation by internal actors.

  • CVE-2026-11510MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its administrative interface. An authenticated attacker can manipulate the type_of_leave parameter when submitting leave requests through /admin/add_leave.php to inject malicious SQL commands. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid administrative credentials to exploit, but public exploit code is now available, increasing the practical risk.

  • CVE-2026-11513MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the adminaccount.php file. An authenticated attacker can manipulate the Date parameter to inject arbitrary SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires valid login credentials but can be exploited over the network. Public exploits are available.

  • CVE-2026-11514MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in the patient admission form. An authenticated attacker can manipulate the admission time parameter in the /addpatient.php file to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials but can be exploited remotely with no additional user interaction.

  • CVE-2026-11529MEDIUM 6.3

    A SQL injection vulnerability exists in the mysql-mcp-server component (versions up to 0.2.2) that allows authenticated users to execute arbitrary SQL commands by manipulating URI parameters. An attacker with valid credentials can read, modify, or delete database records. The vulnerability has been publicly disclosed, increasing immediate risk. Upgrading to version 0.3.0 eliminates the issue.

  • CVE-2026-11558MEDIUM 6.3

    CodeAstro Payroll System version 1.0 contains a SQL injection vulnerability in the /home_salary.php file. An authenticated attacker can manipulate the rate or salary_rate parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete sensitive payroll data. The vulnerability requires a valid user login but can be exploited over the network without user interaction once authenticated.

  • CVE-2026-11559MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Payroll System version 1.0 that allows authenticated users to manipulate database queries through the ID parameter in the /view_account.php file. An attacker with valid credentials can inject malicious SQL commands to access, modify, or delete sensitive payroll data. The vulnerability is network-accessible and does not require additional user interaction, though authentication is required. Public exploits are now available, increasing the risk of active exploitation.

  • CVE-2026-11583MEDIUM 6.3

    CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in the class creation administrative function. An authenticated attacker can manipulate the className input parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid login credentials but can be exploited over the network without additional user interaction.

  • CVE-2026-11584MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Student Attendance Management System version 1.0 that allows authenticated users to manipulate a parameter in the class editing interface and execute arbitrary database commands. An attacker with login credentials can inject malicious SQL through the ID argument to read, modify, or delete sensitive student and attendance data. The vulnerability is network-accessible and exploit code has been publicly disclosed, increasing the practical attack surface.

  • CVE-2026-11585MEDIUM 6.3

    CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its class management functionality. An authenticated attacker can manipulate the classId parameter in the createClassArms.php file to inject malicious SQL commands, potentially allowing unauthorized access to or modification of the database. The vulnerability requires user authentication but can be exploited remotely without user interaction.

  • CVE-2026-12131MEDIUM 6.3

    CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its Payroll Invoice Module. An authenticated attacker can manipulate the ID parameter in the invoice function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials to exploit but has low complexity and is accessible over the network. Public exploit code now exists, elevating the practical risk.

  • CVE-2026-12188MEDIUM 6.3

    Grit42 Grit versions up to 0.11.0 contain a SQL injection vulnerability in the GritEntityController component. An authenticated attacker can manipulate input to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive data. The vulnerability requires valid login credentials but can be exploited over the network without user interaction. Public exploits are available.

  • CVE-2026-12206MEDIUM 6.3

    Grit42's Grit framework versions up to 0.11.0 contain a SQL injection flaw in the DataTableEntity component. An authenticated attacker can exploit this remotely by manipulating input to the affected function, potentially allowing unauthorized access to, modification of, or deletion of database records. Public exploits exist for this vulnerability, elevating urgency for organizations using affected versions.

  • CVE-2026-12219MEDIUM 6.3

    Yealink SIP-T46U phone systems running firmware version 108.86.0.118 contain a command injection vulnerability in their web-based diagnostic interface. An authenticated user can exploit this flaw by manipulating a time parameter to execute arbitrary system commands on the affected device. The vulnerability has been disclosed publicly, meaning attackers have knowledge of how to exploit it. Upgrading to firmware version 108.87.0.23 eliminates the risk.

  • CVE-2026-12776MEDIUM 6.3

    Montodel House-Rental-Management contains a SQL injection vulnerability in its house listing functionality that allows authenticated attackers to manipulate database queries by injecting malicious SQL code through the ID parameter. An attacker with valid login credentials can exploit this remotely to read, modify, or delete sensitive rental property and customer data. Public exploit code is available, increasing the likelihood of active exploitation.

  • CVE-2026-12807MEDIUM 6.3

    A command injection vulnerability exists in Edimax BR-6478AC V2 running firmware version 1.23. An authenticated attacker can send a specially crafted request to the router's WAN configuration endpoint to inject and execute arbitrary system commands. The vulnerability affects parameters used to configure PPP, PPTP, and L2TP username fields. Because the flaw requires an authenticated session and exploits have already been disclosed publicly, this poses a meaningful risk to organizations running this router model, particularly in environments where internal threat actors or compromised accounts could be leveraged.

  • CVE-2026-12808MEDIUM 6.3

    A command injection vulnerability has been discovered in Edimax BR-6478AC V2 running firmware version 1.23. An authenticated attacker can manipulate the 'interface' parameter in a POST request to the /goform/stainfo endpoint to execute arbitrary system commands. The vulnerability requires valid login credentials but poses a meaningful risk to organizations relying on this router model, particularly in environments where user accounts may be compromised or where trust boundaries are weak.

  • CVE-2026-12809MEDIUM 6.3

    A command injection vulnerability exists in Edimax BR-6478AC V2 running firmware 1.23. An authenticated attacker can manipulate the 'newpass' parameter in the wiz_5in1_redirect function to inject arbitrary commands, potentially compromising device integrity and data confidentiality. The vulnerability requires valid login credentials to exploit and is reachable over the network. Public exploit code is available.

  • CVE-2026-12810MEDIUM 6.3

    Edimax BR-6478AC V2 routers running firmware 1.23 contain a command injection vulnerability in their web management interface. An authenticated attacker can manipulate input to the mp endpoint and execute arbitrary system commands on the device. The vulnerability requires valid login credentials but no special privileges, and the exploit code is publicly available.

  • CVE-2026-13496MEDIUM 6.3

    CVE-2026-13496 is a SQL injection vulnerability in itsourcecode Hospital Management System version 1.0. An authenticated user can manipulate the medicineid parameter in the /ajaxmedicine.php file to inject malicious SQL commands, potentially allowing them to read, modify, or delete database records. The vulnerability requires login credentials but can be exploited remotely over the network. Public exploit code is available, increasing the practical risk.

  • CVE-2026-13497MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 that allows authenticated users to manipulate database queries through the editid parameter in the appointment.php file. An attacker with valid credentials can exploit this flaw to read, modify, or delete sensitive hospital data, including patient records and appointment information. The vulnerability has been publicly disclosed, meaning exploitation guidance may be available to threat actors.

  • CVE-2026-13520MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in its appointment approval handler. An authenticated user can manipulate the 'editid' parameter in the /appointmentapproval.php file to inject SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid login credentials but poses genuine risk to hospitals relying on this system for critical appointment data. Public exploit code is available, raising the urgency of remediation.

  • CVE-2026-13525MEDIUM 6.3

    CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its leave update functionality. An authenticated user can manipulate the employee ID parameter to inject malicious SQL commands, potentially exposing, modifying, or deleting sensitive HR data. The vulnerability has been publicly disclosed and exploitation code is available.