|
431
|
9.8 |
CRITICAL
Network
|
-
|
-
|
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.
Update
|
CWE-89
SQL Injection
|
CVE-2025-65135
|
2026-04-18 00:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
6.1 |
MEDIUM
Network
|
-
|
-
|
In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2025-65136
|
2026-04-18 00:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
9.9 |
CRITICAL
Network
|
-
|
-
|
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-38526
|
2026-04-18 00:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
8.5 |
HIGH
Network
|
-
|
-
|
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-38527
|
2026-04-18 00:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
7.1 |
HIGH
Network
|
-
|
-
|
Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-38528
|
2026-04-18 00:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37590
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
2.7 |
LOW
Network
|
-
|
-
|
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37591
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
2.7 |
LOW
Network
|
-
|
-
|
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37592
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37593
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37594
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|