|
781
|
3.5 |
LOW
Network
|
-
|
-
|
A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[locale]/(auth)/reset-password/components/reset-password-form.tsx of the component…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6493
|
2026-04-18 00:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
782
|
7.3 |
HIGH
Network
|
-
|
-
|
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.
|
CWE-89
SQL Injection
|
CVE-2026-37336
|
2026-04-18 00:15 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
783
|
7.3 |
HIGH
Network
|
-
|
-
|
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php.
|
CWE-89
SQL Injection
|
CVE-2026-37337
|
2026-04-18 00:15 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
784
|
9.4 |
CRITICAL
Network
|
-
|
-
|
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.
|
CWE-89
SQL Injection
|
CVE-2026-37338
|
2026-04-18 00:15 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
785
|
9.8 |
CRITICAL
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.
|
CWE-89
SQL Injection
|
CVE-2026-37345
|
2026-04-18 00:15 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
786
|
4.7 |
MEDIUM
Network
|
-
|
-
|
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.
|
CWE-89
SQL Injection
|
CVE-2026-37346
|
2026-04-18 00:15 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
787
|
9.1 |
CRITICAL
Network
|
-
|
-
|
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.
|
CWE-89
SQL Injection
|
CVE-2026-37347
|
2026-04-18 00:15 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
788
|
8.2 |
HIGH
Network
|
-
|
-
|
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-3324
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
789
|
5.1 |
MEDIUM
Physics
|
-
|
-
|
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leadi…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2025-36579
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
790
|
4.1 |
MEDIUM
Local
|
-
|
-
|
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially explo…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2025-43883
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|