Total
20763 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-37601 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php. | |||||
| CVE-2026-37600 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php. | |||||
| CVE-2026-37598 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings. | |||||
| CVE-2026-37597 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php. | |||||
| CVE-2026-37596 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php. | |||||
| CVE-2026-37595 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php. | |||||
| CVE-2026-37594 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php. | |||||
| CVE-2026-37593 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php. | |||||
| CVE-2026-37592 | 2026-06-17 | N/A | 2.7 LOW | ||
| Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php. | |||||
| CVE-2026-37591 | 2026-06-17 | N/A | 2.7 LOW | ||
| Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php. | |||||
| CVE-2026-37590 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php. | |||||
| CVE-2026-37589 | 2026-06-17 | N/A | 2.7 LOW | ||
| SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php. | |||||
| CVE-2026-37505 | 1 V2board | 1 V2board | 2026-06-17 | N/A | 4.9 MEDIUM |
| SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort parameter from user input is passed directly to User::orderBy($sort, $sortType) without validation. An authenticated admin can sort users by any database column including password, remember_token, and other sensitive fields, enabling information disclosure through ordering analysis. | |||||
| CVE-2026-37431 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | |||||
| CVE-2026-37429 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII) via a crafted SQL statement. | |||||
| CVE-2026-37428 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII). | |||||
| CVE-2026-37347 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. | |||||
| CVE-2026-37346 | 2026-06-17 | N/A | 4.7 MEDIUM | ||
| SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=. | |||||
| CVE-2026-37345 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. | |||||
| CVE-2026-37344 | 2026-06-17 | N/A | 7.2 HIGH | ||
| SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php. | |||||
