Total
4091 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-14968 | 1 Carmelo | 1 Simple Stock System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown functionality of the file /market/update.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
|
|||||
| CVE-2025-14966 | 1 Fastadmin | 1 Fastadmin | 2026-02-24 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file application/common/controller/Backend.php of the component Backend Controller. Executing a manipulation of the argument custom/searchField can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
|
|||||
| CVE-2025-14959 | 1 Carmelo | 1 Simple Stock System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of the file /market/signup.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
|
|||||
| CVE-2025-14952 | 1 Campcodes | 1 Supplier Management System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Performing a manipulation of the argument txtCategoryName results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
|
|||||
| CVE-2025-14950 | 1 Fabian | 1 Scholars Tracking System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
|
|||||
| CVE-2025-14899 | 1 Codeastro | 1 Real Estate Management System | 2026-02-24 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /admin/stateadd.php of the component Administrator Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
|
|||||
| CVE-2025-14898 | 1 Codeastro | 1 Real Estate Management System | 2026-02-24 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component Administrator Endpoint. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
|
|||||
| CVE-2025-14856 | 1 Ruoyi | 1 Ruoyi | 2026-02-24 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
|
|||||
| CVE-2025-14834 | 1 Carmelo | 1 Simple Stock System | 2026-02-24 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
|
|||||
| CVE-2025-14694 | 2026-02-24 | 5.8 MEDIUM | 4.7 MEDIUM | ||
|
A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/postil/readAllPostil. Performing a manipulation of the argument keyWord results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-14674 | 2026-02-24 | 6.5 MEDIUM | 6.3 MEDIUM | ||
|
A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java. The manipulation results in injection. The attack can be launched remotely. Upgrading to version 1.7.0-beta1 addresses this issue. The patch is identified as 978f316c38b3d68bb74d2489b5e5f721f6675e86. The affected component should be ...
Show More |
|||||
| CVE-2025-14668 | 1 Campcodes | 1 Advanced Online Examination System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
|
|||||
| CVE-2025-14589 | 1 Carmelo | 1 Prison Management System | 2026-02-24 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing a manipulation of the argument keyname can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
|
|||||
| CVE-2025-14566 | 1 Kidaze | 1 Courseselectionsystem | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function of the file /Profilers/SProfile/reg.php. Performing a manipulation of the argument USN results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
|
|||||
| CVE-2025-14565 | 1 Kidaze | 1 Courseselectionsystem | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/SProfile/login1.php. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
|
|||||
| CVE-2025-14527 | 1 Projectworlds | 1 Advanced Library Management System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A weakness has been identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /view_book.php. Executing a manipulation of the argument book_id can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
|
|||||
| CVE-2025-14276 | 2026-02-24 | 5.1 MEDIUM | 5.6 MEDIUM | ||
|
A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the argument line causes command injection. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. Upgrading the affected component is recommended. The vendor confirms the issue and recommend ...
Show More |
|||||
| CVE-2025-14212 | 1 Projectworlds | 1 Advanced Library Management System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /member_search.php. Executing a manipulation of the argument roll_number can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
|
|||||
| CVE-2025-14211 | 1 Projectworlds | 1 Advanced Library Management System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_book.php. Performing a manipulation of the argument book_id results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
|
|||||
| CVE-2025-14209 | 1 Campcodes | 1 School File Management System | 2026-02-24 | 7.5 HIGH | 7.3 HIGH |
|
A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the file /update_query.php. This manipulation of the argument stud_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
|
|||||
| CVE-2025-14193 | 1 Carmelogarcia | 1 Employee Profile Management System | 2026-02-24 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file /view_personnel.php. Executing a manipulation of the argument per_id can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
|
|||||
| CVE-2025-14012 | 1 Jizhicms | 1 Jizhicms | 2026-02-24 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/Comment/deleteAll.html of the component Batch Delete Comments. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-14011 | 1 Jizhicms | 1 Jizhicms | 2026-02-24 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Comment/addcomment.html of the component Add Display Name Field. Performing a manipulation of the argument aid/tid results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2026-27194 | 1 Man | 1 D-tale | 2026-02-23 | N/A | 9.8 CRITICAL |
|
D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue has been fixed in version 3.20.0.
|
|||||
| CVE-2026-2867 | 1 Admerc | 1 Vehicle Management System | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
|
|||||
| CVE-2026-2691 | 1 Admerc | 1 Event Management System | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2026-2706 | 1 Code-projects | 1 Patient Record Management System | 2026-02-23 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the file /fecalysis_not.php. This manipulation of the argument comp_id causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
|
|||||
| CVE-2026-2912 | 1 Fabian | 1 Online Reviewer System | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation of the argument test_id results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
|
|||||
| CVE-2020-16875 | 1 Microsoft | 1 Exchange Server | 2026-02-23 | 9.0 HIGH | 8.4 HIGH |
|
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p>
<p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.</p>
<p>The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.</p>
|
|||||
| CVE-2026-27022 | 2026-02-23 | N/A | 6.5 MEDIUM | ||
|
@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these charact ...
Show More |
|||||
| CVE-2026-2963 | 2026-02-23 | 6.5 MEDIUM | 6.3 MEDIUM | ||
|
A vulnerability was determined in Jinher OA C6 up to 20260210. This issue affects some unknown processing of the file /C6/Jhsoft.Web.officesupply/OfficeSupplyTypeRight.aspx. This manipulation of the argument id/offsnum causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2026-27203 | 2026-02-23 | N/A | 8.3 HIGH | ||
|
eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to Environment Variable Injection through the updateEnvFile function. The ebay_set_user_tokens tool allows updating the .env file with new tokens. The updateEnvFile function in src/auth/oauth.ts blindly appends or replaces values without validating them for newlines or quotes. This allows an attacker to inject arbitrary environment variables in ...
Show More |
|||||
| CVE-2026-2227 | 1 Dlink | 2 Dcs-931l, Dcs-931l Firmware | 2026-02-23 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
|
|||||
| CVE-2026-2225 | 1 Clive 21 | 1 News Portal Project | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
|
|||||
| CVE-2026-2171 | 1 Fabian | 1 Online Student Management System | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argument username/password results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
|
|||||
| CVE-2026-1125 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
|
|||||
| CVE-2026-1050 | 2026-02-23 | 7.5 HIGH | 7.3 HIGH | ||
|
A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2026-0701 | 1 Carmelo | 1 Intern Membership Management System | 2026-02-23 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /intern/admin/add_admin.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
|
|||||
| CVE-2026-0607 | 1 Fabian | 1 Online Music Site | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
|
|||||
| CVE-2026-0605 | 1 Fabian | 1 Online Music Site | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
|
|||||