By severity
High-severity vulnerabilities
CVEs rated High by CVSS, with SEC.co remediation and prioritization guidance.
4140 published vulnerabilities · page 36 of 42
- CVE-2026-11437HIGH 7.3
A vulnerability in go-fastdfs-web versions up to 1.3.7 allows attackers to make the affected server fetch or interact with arbitrary external resources without authorization. An unauthenticated attacker can manipulate a parameter in the installation endpoint's server check function to trigger server-side requests to unintended destinations. This is particularly dangerous because the server performs actions on behalf of the attacker, potentially accessing internal systems, exfiltrating data, or pivoting to other infrastructure that trusts the vulnerable server.
- CVE-2026-11450HIGH 7.3
A command injection vulnerability exists in GL.iNet GL-MT3000 routers running firmware version 4.4.5 and earlier. An attacker can remotely exploit this flaw by manipulating the device name parameter in the HTTP RPC interface, allowing them to execute arbitrary commands on the affected device without authentication. The issue stems from insufficient input validation in the path normalization handler. GL.iNet has addressed this in firmware version 4.7 and later by implementing method-level validation that prevents the vulnerable eject_disk function from being called through the default RPC endpoint.
- CVE-2026-11451HIGH 7.3
GL.iNet's GL-MT3000 router firmware version 4.4.5 contains a command injection vulnerability in its FTP configuration handler. An attacker can remotely manipulate the media_dir parameter to inject and execute arbitrary shell commands without authentication. The vulnerability has been patched in firmware version 4.8.1, where the vendor implemented input escaping to neutralize quote-based command injection payloads.
- CVE-2026-11452HIGH 7.3
A command injection vulnerability exists in GL.iNet's GL-MT3000 router firmware versions up to 4.4.5. An attacker can remotely send a specially crafted password parameter to the SET_USER_PWD handler in the /cgi-bin/glc component, allowing arbitrary command execution on the device without authentication. The vulnerability stems from insufficient input validation when processing password input. GL.iNet has addressed this issue in firmware version 4.8.1 by properly escaping shell metacharacters and containing the password parameter within a safe execution context.
- CVE-2026-11456HIGH 7.3
Chanjet CRM 1.0 contains a SQL injection vulnerability in its HTTP GET request handler, specifically in the /tools/jxf_dump_systable.php file. An attacker can manipulate the gblOrgID parameter to inject malicious SQL commands, potentially allowing unauthorized access to or modification of database contents. The vulnerability requires no authentication and can be exploited over the network. Exploit code is publicly available, increasing the risk of active exploitation.
- CVE-2026-11457HIGH 7.3
A vulnerability has been discovered in JeeWMS, an open-source warehouse management system. The flaw exists in the JimuReport test-connection endpoint and allows attackers to manipulate database connection parameters (database type, driver, URL, username, and password) to inject malicious commands. An attacker on the network can exploit this without authentication to compromise the confidentiality, integrity, and availability of the system. Public exploit code is already available, increasing the practical risk.
- CVE-2026-11460HIGH 7.3
Boost Serialization, a widely-used C++ library for object serialization, contains a validation flaw that allows remote attackers to send specially crafted input that bypasses security checks. The vulnerability affects all versions up to 1.91 and can lead to information disclosure, data tampering, or service disruption. No patch currently exists, and the vendor has indefinitely postponed fixing it despite being notified in August 2025 and exceeding the 90-day disclosure deadline.
- CVE-2026-11462HIGH 7.3
BeikeShop, an e-commerce platform by Chengdu Everbrite Network Technology, contains an authorization flaw in its Stripe payment plugin that allows unauthenticated attackers to manipulate request parameters and gain unauthorized access to sensitive functions. The vulnerability affects versions up to 1.6.0.22 and has been publicly disclosed, increasing exploitation risk. A patch is available and should be deployed promptly.
- CVE-2026-11463HIGH 7.3
USCiLab Cereal, a serialization library used in C++ applications, contains a type confusion vulnerability in how it handles shared pointers during deserialization. An attacker can send specially crafted data over the network to cause the library to misinterpret object types, potentially leading to information disclosure, data corruption, or application crashes. The vulnerability affects versions up to and including 1.3.2, and exploit code has already been publicly shared.
- CVE-2026-11471HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, affecting the password input field on the /index2.php page. An attacker can send a specially crafted login request over the network to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive database records. The attack requires no authentication and can be executed remotely. Public exploit code is available, increasing the risk of opportunistic exploitation.
- CVE-2026-11472HIGH 7.3
SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the Password parameter of /index1.php. An unauthenticated attacker can send specially crafted requests to the application to bypass authentication, extract database contents, or modify data. The vulnerability requires no user interaction and can be exploited over the network. Public exploit code exists, elevating risk significantly.
- CVE-2026-11474HIGH 7.3
A file upload vulnerability has been discovered in Kushan2k's student-management-system that allows attackers to upload files without restriction. The flaw resides in the registration endpoint's service code and is triggered by manipulating the 'stimg' parameter. Because the vulnerability requires no authentication and can be exploited remotely with minimal complexity, it poses an immediate risk to exposed instances. Public exploit code is already available, elevating the likelihood of opportunistic attacks.
- CVE-2026-11482HIGH 7.3
A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can manipulate the 'sy' parameter in the /archive5.php file to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive database records. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-11483HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can send a specially crafted request to the /archive4.php endpoint that manipulates the 'sy' parameter to inject arbitrary SQL commands. Because no authentication is required and the vulnerability can be exploited over the network, a remote attacker can exploit this flaw to read, modify, or delete database records. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-11484HIGH 7.3
A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /archive3.php file where an attacker can manipulate the 'sy' parameter to inject malicious SQL commands. Because no authentication is required and the attack can be carried out over the network, an unauthenticated attacker can exploit this to read, modify, or delete data from the underlying database. Public proof-of-concept code is now available, increasing the likelihood of real-world attacks.
- CVE-2026-11485HIGH 7.3
SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /archive2.php file. An attacker can manipulate the 'sy' parameter to inject malicious SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires no authentication and can be exploited remotely over the network. Public disclosure has occurred, increasing the likelihood of active exploitation.
- CVE-2026-11486HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. The flaw is located in the /archive1.php file, where user input in the 'sy' parameter is not properly sanitized before being used in database queries. An attacker can exploit this remotely without authentication to read, modify, or delete database contents. Public exploit code is available, increasing the practical risk.
- CVE-2026-11488HIGH 7.3
A SQL injection vulnerability exists in Simple Flight Ticket Booking System version 1.0. The flaw resides in the checkUser.php file where user input in the Username parameter is not properly sanitized before being used in database queries. An attacker can exploit this remotely without authentication by submitting malicious SQL code through the POST request, potentially reading, modifying, or deleting database contents. Public disclosure of this vulnerability means active exploitation is a realistic concern.
- CVE-2026-11489HIGH 7.3
A SQL injection vulnerability exists in the Online Music Site application version 1.0, specifically in the album deletion administrative function. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially compromising the database. The vulnerability requires no authentication and can be exploited remotely, making it a significant risk for any instance of this application exposed to untrusted networks.
- CVE-2026-11490HIGH 7.3
A SQL injection vulnerability exists in code-projects Online Music Site version 1.0. The flaw is in the Search.php file where the Category parameter is not properly validated before being used in database queries. An attacker can send a specially crafted request over the network to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability requires no authentication and no user interaction, making it accessible to anyone on the internet. Public exploit code is available.
- CVE-2026-11501HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System version 1.0. An attacker can manipulate the ID parameter in the patient-saving function to inject malicious SQL commands, potentially reading, modifying, or deleting patient records without authentication. The vulnerability is network-accessible and exploit code is publicly available, raising the risk of immediate abuse.
- CVE-2026-11530HIGH 7.3
A SQL injection vulnerability exists in the imvks786 student management system's login component. An attacker can manipulate the username and password parameters to inject malicious SQL commands, potentially gaining unauthorized access to the system or extracting sensitive student data. The vulnerability is remotely exploitable without authentication and does not require user interaction, making it a straightforward attack vector. Public exploit code is available, elevating the risk of active exploitation.
- CVE-2026-11531HIGH 7.3
A SQL injection vulnerability exists in the imvks786 student management system's administrator login endpoint. An attacker can manipulate username and password parameters to inject malicious SQL commands, potentially gaining unauthorized access or extracting sensitive data. The flaw affects the admin/admin_login.php file and can be exploited remotely without authentication. Public exploit code is available, increasing active threat likelihood.
- CVE-2026-11582HIGH 7.3
CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its web-based attendance interface. An attacker can manipulate the Username parameter in the /attendance-php/index.php file to inject malicious SQL commands, potentially allowing unauthorized access to student records, attendance data, or other sensitive information stored in the application's database. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the application.
- CVE-2026-11618HIGH 7.3
DTStack Taier, a data integration platform, contains an authentication bypass vulnerability in its login interceptor component that allows remote attackers to circumvent authentication controls without any credentials or user interaction. The vulnerability affects all versions up to 1.4.0 and has been publicly disclosed, increasing immediate exploitation risk.
- CVE-2026-11837HIGH 7.3
A vulnerability in Ansible's posix authorized_key module allows a local user to escalate their privileges to root. The flaw stems from how the module handles SSH key file operations: it follows symbolic links when changing file ownership instead of operating directly on the link itself. An attacker with a local account can create malicious symbolic links in their .ssh directory, then wait for a system administrator to run an Ansible task that manages authorized keys with elevated privileges. When that happens, the module will change ownership of arbitrary files on the system—potentially giving the attacker control over critical system files and full system access.
- CVE-2026-12066HIGH 7.3
PbootCMS versions up to 3.2.12 contain a flaw in the password recovery mechanism that allows attackers to bypass intended security controls. The vulnerability exists in the component that handles password resets and account recovery, specifically in how it validates and processes recovery-related parameters. An attacker can exploit this remotely without authentication to recover user accounts or reset passwords that should be protected, potentially gaining unauthorized access to user accounts.
- CVE-2026-12198HIGH 7.3
Microweber, a website builder platform, contains a path traversal vulnerability in its API endpoint that handles image thumbnail requests. An attacker can manipulate a cache path parameter to access files outside the intended directory structure, potentially reading sensitive data, modifying files, or disrupting service. The vulnerability affects Microweber versions up to 2.0.20 and can be exploited remotely without authentication. Public exploit code is available, increasing the practical risk.
- CVE-2026-12200HIGH 7.3
TinyWeb Server version 1.94 and earlier on Windows contains a stack-based buffer overflow vulnerability in how it processes the Authorization header. An attacker can send a specially crafted HTTP request with a malicious Authorization header to overflow the server's memory and potentially execute code, crash the service, or access sensitive data. The vulnerability requires no authentication or user interaction to exploit, making it actionable for remote attackers.
- CVE-2026-12204HIGH 7.3
ShopXO, an e-commerce platform, contains a flaw that allows attackers to bypass authentication controls and manipulate critical order and payment functions without proper authorization. The vulnerability affects versions up to 6.7.1 and resides in the scheduled task endpoint responsible for order closure, payment logging, and reward processing. Because no authentication checks guard these functions, a remote attacker can invoke them directly to alter order states, process payments, or award bonuses without logging in. The vulnerability is publicly known and exploit code is available, increasing active risk.
- CVE-2026-12318HIGH 7.3
A boundary condition error in the NSS (Network Security Services) Libraries component affects Mozilla Firefox and Thunderbird. This vulnerability allows attackers to send specially crafted network requests that can leak small amounts of sensitive data, corrupt application state, or crash the affected software. No user interaction is required for exploitation—an attacker on the network or a compromised website could trigger the flaw.
- CVE-2026-12324HIGH 7.3
A boundary condition flaw in Firefox and Thunderbird's WebGL graphics component allows an attacker to send a specially crafted request over the network without authentication or user interaction to cause information disclosure, data manipulation, or denial of service. The vulnerability affects multiple versions of both applications and has been patched in recent releases.
- CVE-2026-12529HIGH 7.3
SourceCodester's CET Automated Grading System with AI Predictive Analytics version 1.0 contains a flaw in its student self-registration function that allows attackers to bypass access controls. An unauthenticated remote attacker can exploit this weakness to gain unauthorized access to system resources. The vulnerability affects the /index.php endpoint and requires no user interaction to trigger.
- CVE-2026-12530HIGH 7.3
A command injection vulnerability exists in the AWS Bedrock AgentCore Python SDK that allows authenticated users to execute arbitrary commands within the Code Interpreter sandbox by manipulating package name arguments. The vulnerability affects versions 1.1.3 through 1.6.0, and AWS has released version 1.6.1 to remediate the issue. An attacker with valid credentials could leverage this flaw to run malicious code with the privileges of the Code Interpreter environment.
- CVE-2026-12773HIGH 7.3
BerriAI's litellm library contains an authentication bypass vulnerability in its MCP (Model Context Protocol) Proxy component. The UserAPIKeyAuth function fails to properly validate API keys, allowing remote attackers to bypass authentication controls without requiring credentials or special privileges. This affects litellm versions up to 1.59.8. Because the vulnerability is network-accessible and the exploit code is publicly available, organizations using affected versions face immediate risk of unauthorized access to their LLM proxy infrastructure.
- CVE-2026-12775HIGH 7.3
A SQL injection vulnerability exists in Montodel House-Rental-Management's login page. An attacker can manipulate the Username parameter in /login.php to inject malicious SQL commands, potentially reading, modifying, or deleting database contents without authentication. The vulnerability is remotely exploitable and requires no user interaction—an attacker can trigger it directly by sending a crafted request. Exploit code is publicly available, increasing the risk of active attacks.
- CVE-2026-12795HIGH 7.3
BerriAI's litellm, an open-source LLM proxy framework, contains an authentication bypass vulnerability in its Single Sign-On (SSO) debug flow. An unauthenticated remote attacker can manipulate the SSO debug endpoint to bypass authentication controls, gaining unauthorized access to the system. The vulnerability affects litellm versions up to and including 1.82.2, and exploit code has already been publicly disclosed.
- CVE-2026-12912HIGH 7.3
A vulnerability in libtiff, a widely-used image processing library, allows a local attacker to trigger a heap-based buffer overflow by opening a specially crafted TIFF image file with PixarLog compression. The flaw surfaces specifically when the decoder processes images using the 8-bit ABGR output format combined with a particular stride configuration. An attacker with local file access could potentially execute arbitrary code on the system or crash the application handling the image.
- CVE-2026-13201HIGH 7.3
KubeVirt's file path handling contains a symlink-following vulnerability that allows attackers with pod-level access to compromise virtual machine management. An attacker in a virt-launcher pod can intercept management socket communications, inject fake VM lifecycle events, or manipulate file ownership on host paths. The result is that virt-handler—the component responsible for VM lifecycle management—can be tricked into corrupting VM state, crashing, or denying service to all VMs on an affected node.
- CVE-2026-13320HIGH 7.3
GitLab has patched a cross-site scripting (XSS) vulnerability that affected users running GitLab Community Edition and Enterprise Edition. The flaw allowed an authenticated attacker with administrative privileges to inject malicious scripts into another user's browser session through inadequately sanitized input fields. Exploitation requires both high-level account access and user interaction (such as a victim clicking a crafted link), limiting the practical attack surface but posing significant risk in environments where admin accounts may be compromised or misused.
- CVE-2026-13485HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, accessible through the /preview.php file. An attacker can manipulate the course_year_section parameter to inject malicious SQL commands, potentially allowing unauthorized data access, modification, or deletion. The vulnerability requires no authentication or user interaction and can be exploited over the network. Public exploit information is available, increasing the practical risk.
- CVE-2026-13486HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, specifically in the /preview6.php file. An attacker can manipulate the 'course_year_section' parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited from the internet. Public exploit code has been released, increasing the practical risk.
- CVE-2026-13487HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can exploit a parameter in the /archive.php file to execute arbitrary SQL commands against the application's database. The vulnerability requires no authentication and can be triggered over the network, making it accessible to remote attackers. Exploit code is already publicly available, increasing the risk of active exploitation.
- CVE-2026-13488HIGH 7.3
A SQL injection vulnerability has been discovered in SourceCodester's Class and Exam Timetabling System version 1.0. The flaw exists in the /preview7.php file and can be exploited by manipulating the 'course_year_section' parameter. An attacker can send a specially crafted request over the internet to execute arbitrary SQL commands against the underlying database, potentially reading, modifying, or deleting sensitive data. The vulnerability requires no authentication or user interaction, and exploit code has already been released publicly, making active exploitation a genuine risk.
- CVE-2026-13498HIGH 7.3
A SQL injection vulnerability exists in the yashpokharna2555 restaurant management system, specifically in the password recovery feature. An attacker can manipulate the email parameter in POST requests to /forgotpassword.php to inject malicious SQL commands. Because the application fails to sanitize user input, an unauthenticated attacker on the internet can execute this attack without special privileges or user interaction, potentially gaining unauthorized access to sensitive database records.
- CVE-2026-13500HIGH 7.3
ANTLR4, a widely-used parser generator framework, contains a code injection vulnerability in how it processes grammar action blocks. An attacker can craft malicious input that manipulates the OutputFile handler to inject and execute arbitrary code during the code generation phase. This flaw requires no authentication and can be triggered remotely, making it a significant concern for anyone using ANTLR4 to build language tools, compilers, or domain-specific languages. The vulnerability affects versions up to and including 4.13.2.
- CVE-2026-13521HIGH 7.3
A SQL injection vulnerability exists in SourceCodester's Class and Exam Timetabling System version 1.0, specifically in the /preview5.php file. An attacker can manipulate the 'course_year_section' parameter to inject malicious SQL commands without needing authentication. The vulnerability allows remote exploitation and poses a meaningful risk to confidentiality, integrity, and availability of affected systems. Exploit code is already publicly available.
- CVE-2026-13526HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can inject malicious SQL commands through the ID parameter in the /edit_class.php file, allowing remote exploitation without authentication. This flaw enables attackers to read, modify, or delete database records. Public exploits are available, increasing the likelihood of active attacks.
- CVE-2026-13527HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 that allows unauthenticated attackers to manipulate database queries through the course_year_section parameter in the /preview4.php file. The vulnerability can be exploited remotely without user interaction, potentially allowing attackers to read, modify, or delete sensitive academic data. Public disclosure of this vulnerability means that attack code is already available, increasing the risk of active exploitation.
- CVE-2026-13528HIGH 7.3
A path traversal vulnerability exists in the file upload functionality of RuoYi-Vue-Pro, an open-source application framework. An attacker can craft a malicious file upload request that bypasses directory restrictions, allowing them to write files outside the intended upload directory. This could lead to unauthorized file creation, modification, or access to sensitive application files. The vulnerability requires no authentication and can be triggered remotely over the network.
- CVE-2026-13546HIGH 7.3
Feehi CMS versions up to 2.1.1 contain a critical flaw in the REST API endpoint for articles (/api/articles) that allows attackers to bypass authentication controls entirely. An attacker can remotely manipulate requests to this endpoint without providing valid credentials, gaining unauthorized access to article data and functionality. This weakness has already been disclosed publicly, increasing the urgency of remediation.
- CVE-2026-13547HIGH 7.3
Hanwang e-Face General Management Platform version 6.3.5.4 contains a file upload vulnerability in its resource upload function. An attacker can bypass upload restrictions by manipulating the File parameter sent to the /manage/resourceUpload/upload.do endpoint, allowing them to upload arbitrary files to the server without authentication. This vulnerability is accessible over the network and has already been disclosed publicly, increasing the risk of active exploitation.
- CVE-2026-13550HIGH 7.3
A SQL injection vulnerability exists in itsourcecode Baptism Information Management System version 1.0. An attacker can send a specially crafted request to the /delbaptism.php file that manipulates the ID parameter to inject malicious SQL commands. This could allow unauthorized access to, modification of, or deletion of data in the underlying database. The vulnerability requires no authentication and can be exploited from the internet by an unauthenticated attacker. Public exploit code has been released, increasing the risk of active attacks.
- CVE-2026-13551HIGH 7.3
itsourcecode's Baptism Information Management System version 1.0 contains a SQL injection vulnerability in its editBaptism.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited remotely, making it a practical concern for organizations running this software. Public exploit disclosure means this risk is elevated in the current threat landscape.
- CVE-2026-13552HIGH 7.3
A SQL injection vulnerability exists in itsourcecode Online Hotel Management System version 1.0 that allows unauthenticated remote attackers to manipulate database queries through the amenities management interface. By tampering with the amen_id parameter in the admin panel, an attacker can execute arbitrary SQL commands without requiring valid credentials or user interaction. The vulnerability has been publicly disclosed and exploit code is available, increasing the practical risk.
- CVE-2026-13553HIGH 7.3
A vulnerability exists in itsourcecode Online Hotel Management System version 1.0 that allows attackers to upload files without restriction through the amenities management interface. An attacker can manipulate the image upload parameter in the admin panel to bypass upload controls and store arbitrary files on the server. This can be exploited remotely without authentication, and active exploit code has already been published.
- CVE-2026-13555HIGH 7.3
itsourcecode Online Hotel Management System version 1.0 contains a SQL injection vulnerability in its admin user management interface. An unauthenticated attacker can send a crafted request to the /admin/mod_users/controller.php endpoint with malicious input in the Name parameter, allowing them to execute arbitrary SQL queries against the backend database. This could lead to unauthorized data access, modification, or deletion. Public exploit code exists for this vulnerability, increasing the immediate risk.
- CVE-2026-13559HIGH 7.3
A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the single-list_sale.php file. An unauthenticated attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. The vulnerability is remotely exploitable and public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-13565HIGH 7.3
SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_class1.php endpoint. An unauthenticated attacker can manipulate the ID parameter to inject arbitrary SQL commands, potentially reading, modifying, or deleting database records. The vulnerability is remotely exploitable without authentication and has been publicly disclosed, meaning attack code may be in active circulation.
- CVE-2026-13566HIGH 7.3
A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /preview3.php file, where user-supplied input in the course_year_section parameter is not properly sanitized before being used in database queries. An attacker can send a specially crafted request to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive academic data. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-13568HIGH 7.3
A flaw in SourceCodester Inventory Management System version 1.0 allows unauthenticated attackers to manipulate user roles during registration, bypassing access controls. An attacker can send a crafted request to the user registration endpoint that assigns themselves elevated privileges, gaining unauthorized access to system functions. Because this requires no authentication and can be exploited over the network, the risk is substantial. Public exploit code now exists, increasing real-world attack likelihood.
- CVE-2026-13592HIGH 7.3
A flaw in liftoff-sr CIPster allows an attacker on the network to send specially crafted EtherNet IP messages that cause the BufWriter::append function to write data beyond allocated memory boundaries. This out-of-bounds write vulnerability can corrupt data, crash the service, or potentially enable code execution. The vulnerability affects versions up to commit e8e9dba09bf56962807d3504b783ccdb6287f3e4, and a public exploit is now available, making active exploitation more likely.
- CVE-2026-13760HIGH 7.3
AWS CDK (Cloud Development Kit) versions prior to 2.260.0 contain a command injection flaw in the Docker bundling pipeline used for Node.js functions. An attacker who can modify the version strings of dependencies in your project's package.json file can inject shell commands that execute with the privileges of the user running the CDK toolchain. This is a local attack that requires an insider or someone with write access to your source repository.
- CVE-2026-14622HIGH 7.3
An authentication bypass vulnerability exists in jairiidriss restaurant-website-php-mysql, a PHP/MySQL application for restaurant management. The flaw resides in the AJAX endpoint handler at /admin/ajax_files, where insufficient authentication checks allow unauthenticated attackers to manipulate functionality remotely. Because the project uses a rolling release model, traditional version tracking is unavailable; however, the vulnerability has been confirmed in commits up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. Public exploit code is available, elevating practical risk.
- CVE-2026-14635HIGH 7.3
A path traversal vulnerability has been discovered in the Ecommerce-CodeIgniter-Bootstrap project that allows remote attackers to manipulate file paths through the vendor multi-image upload feature. By altering the folder parameter sent to the AddProduct.php controller, an attacker can access files and directories outside the intended upload location. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-14640HIGH 7.3
CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its login functionality. An attacker can manipulate the Username parameter on the /index.php login page to inject malicious SQL commands, bypassing authentication and potentially accessing sensitive data. The vulnerability requires no authentication or user interaction to exploit and can be executed remotely over the network. Public exploit code is available, increasing the immediate risk to deployed systems.
- CVE-2026-14641HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, accessible through the /edit_course.php endpoint. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially extracting, modifying, or deleting database records. No authentication is required, and the vulnerability can be exploited over the network. Public disclosure means threat actors have ready-made exploitation techniques available.
- CVE-2026-14642HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 in the /edit_class2.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to or modification of the database. The vulnerability requires no authentication and can be exploited remotely. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-14648HIGH 7.3
A SQL injection vulnerability exists in code-projects Online Voting System affecting versions up to 0.x/1.0. The flaw resides in the login authentication component, specifically in how the system processes the adminUserName and adminPassword parameters. An attacker can bypass authentication and manipulate the underlying database by injecting malicious SQL commands through these input fields. Because the vulnerability allows unauthenticated remote exploitation and the exploit code is publicly available, it poses an immediate threat to any organization running this voting system.
- CVE-2026-14649HIGH 7.3
A SQL injection vulnerability exists in code-projects Online Voting System version 1.0. The vulnerability affects the voting submission functionality, specifically the `/saveVote.php` file's `test_input` function. An attacker can manipulate voter-related fields (voterName, voterEmail, voterID, or selectedCandidate) to inject malicious SQL commands. Because the vulnerability requires no authentication and can be triggered remotely over the network, an attacker can exploit it without prior system access or user interaction.
- CVE-2026-14652HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the username field on the admin login page. This could enable attackers to bypass authentication, extract sensitive data, modify database contents, or cause system disruption. The vulnerability is network-accessible and requires no user interaction or authentication to exploit, making it immediately actionable for threat actors. Public exploit information is available, increasing real-world attack probability.
- CVE-2026-14653HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. The vulnerability is located in the admin panel at /admin/mensproductdeletequery.php and can be exploited by manipulating the user_id parameter. An attacker can send a specially crafted request over the network without authentication to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. Public exploit code is available, elevating the immediate risk.
- CVE-2026-14654HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. An attacker can manipulate the user_id parameter in the /admin/girlsproductdeletequery.php file to inject malicious SQL commands. Because this admin endpoint requires no authentication and can be accessed over the network, an unauthenticated remote attacker can exploit this flaw to read, modify, or delete database contents. Public exploits are already available, increasing the practical risk.
- CVE-2026-14660HIGH 7.3
A SQL injection vulnerability exists in code-projects Online Job Portal version 1.0 that allows unauthenticated attackers to manipulate login credentials and execute arbitrary SQL queries. The vulnerability is in the login.php file, specifically in how it processes the txtUser and txtPass parameters. An attacker can craft malicious input to bypass authentication, extract sensitive data, or modify the database. Public exploit information is available, increasing the risk of active exploitation.
- CVE-2026-14688HIGH 7.3
itsourcecode Online Hotel Management System version 1.0 contains a SQL injection vulnerability in its admin login functionality. An attacker can exploit a flaw in how the system processes the email parameter to inject malicious SQL commands without authentication, potentially exposing or modifying sensitive data in the underlying database. The vulnerability is network-accessible and proof-of-concept exploits are publicly available.
- CVE-2026-14690HIGH 7.3
A security flaw in SourceCodester Multi-Vendor Online Grocery Management System version 1.0 allows attackers to bypass authorization controls in the user management function. The vulnerability exists in the save_users function within classes/Users.php and can be exploited remotely by unauthenticated attackers without any user interaction required. Because exploit code has been publicly released, the risk of active attacks is elevated.
- CVE-2026-14695HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Multi-Vendor Online Grocery Management System version 1.0, specifically in the user registration function. An attacker can send a malicious request with a specially crafted name field to bypass input validation and execute arbitrary SQL commands against the backend database. No authentication is required, and the vulnerability can be exploited over the network. Public proof-of-concept code has been released, making this an active threat.
- CVE-2026-14700HIGH 7.3
A SQL injection vulnerability exists in the Employer Login Endpoint of code-projects Internship Management System version 1.0. An attacker can inject malicious SQL commands through the email or password login fields without authentication, potentially accessing, modifying, or deleting sensitive data in the application's database. The vulnerability is accessible over the network and has been publicly disclosed, making active exploitation more likely.
- CVE-2026-14705HIGH 7.3
A SQL injection vulnerability exists in code-projects Online Examination version 1.0 that allows unauthenticated attackers to manipulate user credentials (uname/password parameters) passed to the head.php file, potentially extracting sensitive data, modifying records, or disrupting service availability. The vulnerability is network-accessible, requires no user interaction, and has been publicly disclosed with exploitation details available.
- CVE-2026-14713HIGH 7.3
SourceCodester Pizzafy E-Commerce System version 1.0 contains a SQL injection vulnerability in its admin panel. An attacker can manipulate the ID parameter in the /admin/ajax.php?action=confirm_order endpoint to execute arbitrary SQL commands without authentication. Because the vulnerability is remotely exploitable and requires no user interaction, it poses a significant risk to affected systems. Public exploit code is available, increasing the likelihood of active attacks.
- CVE-2026-14719HIGH 7.3
A vulnerability in SourceCodester Online Examination & Learning Management System version 1.0 allows an unauthenticated attacker to manipulate user roles during registration. By tampering with the role parameter sent to the registration endpoint, an attacker can escalate their privileges without proper authorization. This flaw is network-accessible, requires no authentication, and can be exploited remotely with a straightforward attack that does not require user interaction. Public exploit code has been disclosed.
- CVE-2026-14722HIGH 7.3
TidGi-Desktop, a desktop application for managing TiddlyWiki repositories, contains a code injection vulnerability affecting versions up to 0.13.0. An attacker can exploit this flaw remotely without authentication to inject and execute arbitrary code. Because exploit code has already been published, the risk of active attacks is elevated. The vulnerability exists in the Git Repository Import functionality, which processes wiki tiddlers from external sources.
- CVE-2026-14732HIGH 7.3
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 affecting the /edit_exam.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the practical risk.
- CVE-2026-14733HIGH 7.3
SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_coursea.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially gaining unauthorized access to or modifying the underlying database. This vulnerability requires no authentication and can be exploited remotely over the network. Public exploits are currently available.
- CVE-2026-14734HIGH 7.3
A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /edit_product.php file where user-supplied input in the ID parameter is not properly validated before being used in database queries. An attacker can exploit this remotely without authentication to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive data. Public exploit code is available, elevating the practical risk.
- CVE-2026-14735HIGH 7.3
A SQL injection vulnerability exists in code-projects Smart Parking System version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the street, city, or status parameters in the /parkings/parkings.php file. An attacker can exploit this remotely without any user interaction to read, modify, or delete database contents. The vulnerability has been publicly disclosed, increasing the immediate risk of active exploitation.
- CVE-2026-14736HIGH 7.3
Ruijie RG-UAC contains a file upload vulnerability in the user_auth_commit.php script that allows unauthenticated attackers to upload arbitrary files. By manipulating the upload_image parameter, an attacker can bypass upload restrictions remotely without authentication. The vulnerability affects versions up to 1.0-R1.8.2.p5, and public exploits are available, increasing active exploitation risk.
- CVE-2026-14737HIGH 7.3
A SQL injection flaw exists in Hanwang e-Face General Management Platform version 6.3.5.4 affecting the /sysAuthStr/querySysAuthStr.do endpoint. By manipulating the order of function arguments, an attacker can inject malicious SQL commands without authentication. The vulnerability can be exploited remotely and proof-of-concept code is publicly available, raising the risk of active exploitation.
- CVE-2026-14743HIGH 7.3
A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the /normalHomeSale.php file. An attacker can manipulate the 'loc' parameter to inject malicious SQL commands, potentially gaining unauthorized access to the database. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the affected application. A public exploit is already available, increasing the practical risk.
- CVE-2026-14744HIGH 7.3
A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the /normalHomeRental.php file. The flaw allows attackers to manipulate the 'loc' parameter to execute arbitrary SQL commands against the application's database. Since this vulnerability can be triggered remotely without authentication, and exploit code has been publicly released, organizations using this software face active exploitation risk.
- CVE-2026-14745HIGH 7.3
A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows unauthenticated attackers to manipulate the ID parameter in the /single-list_rent.php file, potentially exposing or altering sensitive data in the underlying database. The vulnerability can be exploited remotely without authentication, and proof-of-concept code is publicly available, increasing the risk of active exploitation.
- CVE-2026-14746HIGH 7.3
A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows unauthenticated remote attackers to manipulate the 'amen' parameter in the /addprojectrent.php file to execute arbitrary SQL queries. The vulnerability has been publicly disclosed and exploitation code is available, increasing the risk of active exploitation. Any organization running this real estate management application should treat this as a high-priority security issue requiring immediate patching or mitigation.
- CVE-2026-14747HIGH 7.3
A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows an unauthenticated attacker to inject malicious SQL commands through the 'amen' parameter in the /addprojectsale.php file. Because no authentication is required and the vulnerability can be exploited over the network, an attacker could potentially read, modify, or delete database records without legitimate access. This is a remotely exploitable flaw affecting a real estate management application.
- CVE-2026-14749HIGH 7.3
A code injection vulnerability exists in mjperpinosa stumasy that allows remote attackers to execute arbitrary code through a parameter in the calculator application. An attacker can send a specially crafted mathematical expression to the eval function without authentication, potentially compromising the affected system. The vulnerability has been publicly disclosed and working exploits are available, raising the urgency of remediation.
- CVE-2026-14750HIGH 7.3
A SQL injection vulnerability has been identified in mjperpinosa stumasy, a project using continuous rolling releases. An attacker can manipulate the Password parameter in the Notes controller's dictionary authorization function to inject malicious SQL commands, potentially compromising database integrity and extracting sensitive information. The flaw is remotely exploitable without requiring authentication, and proof-of-concept code has already been released publicly, increasing the risk of active exploitation.
- CVE-2026-14753HIGH 7.3
A vulnerability in mjperpinosa stumasy allows attackers to bypass authorization controls by manipulating the assignment_item_id parameter. The flaw exists in the Note Handler/Assignment Handler component, which processes note assignments through the /PHP/objects/notes file. An unauthenticated attacker on the network can exploit this remotely without user interaction to gain unauthorized access to functionality or data they shouldn't be able to reach. Public exploit information is now available, elevating the practical risk.
- CVE-2026-14754HIGH 7.3
A SQL injection vulnerability exists in Hotel and Tourism Reservation version 1.0, specifically in the admin room management interface. An unauthenticated attacker can manipulate several input parameters—including room description, price, type, number, and image deletion fields—to execute arbitrary SQL commands against the backend database. The vulnerability requires no user interaction and can be exploited remotely, making it a direct network-based attack surface.
- CVE-2026-14755HIGH 7.3
A SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation system version 1.0. The flaw is located in the reservations management page at /admin/reservations.php, where user input passed through the 'delete' parameter is not properly validated before being used in database queries. An unauthenticated attacker on the network can exploit this remotely to read, modify, or delete sensitive reservation data and potentially gain deeper access to the system. Public disclosure means defensive awareness is urgent.
- CVE-2026-14756HIGH 7.3
A SQL injection vulnerability exists in the Hotel and Tourism Reservation system (version 1.0) that allows unauthenticated attackers to manipulate database queries through the tour deletion function. An attacker can send a specially crafted request to the `/admin/add_tour.php` page targeting the `delete_image` parameter to execute arbitrary SQL commands, potentially accessing, modifying, or deleting sensitive reservation and customer data. The vulnerability requires no special privileges or user interaction, making it straightforward to exploit over the network. Public exploit information is already available, elevating the urgency of patching.
- CVE-2026-14762HIGH 7.3
A SQL injection vulnerability exists in the Hotel and Tourism Reservation system version 1.0, specifically in the room management administrative interface. An attacker can manipulate the 'delete' parameter in the /admin/rooms.php file to execute unauthorized database queries without authentication. This allows remote attackers to read, modify, or delete sensitive data from the reservation system's database. The vulnerability is now public and active exploits are known to exist.