|
311
|
2.7 |
LOW
Network
|
-
|
-
|
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/clients/manage_client.php
Update
|
CWE-89
SQL Injection
|
CVE-2026-36945
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312
|
2.7 |
LOW
Network
|
-
|
-
|
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-36937
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313
|
2.7 |
LOW
Network
|
-
|
-
|
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-36938
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314
|
7.3 |
HIGH
Network
|
-
|
-
|
Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-36948
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315
|
2.7 |
LOW
Network
|
-
|
-
|
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-36950
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
316
|
2.7 |
LOW
Network
|
-
|
-
|
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-36952
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317
|
7.2 |
HIGH
Network
|
-
|
-
|
Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads into POST parameters. Attackers can i…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-40038
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
318
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious l…
Update
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2026-40039
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319
|
8.8 |
HIGH
Network
|
-
|
-
|
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-40040
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in authenticated user context by exploiting missing CSRF protections on state-chang…
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-40041
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|