|
51
|
7.2 |
HIGH
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37344
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
7.2 |
HIGH
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37343
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
7.2 |
HIGH
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37342
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
7.2 |
HIGH
Network
|
-
|
-
|
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37341
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
9.8 |
CRITICAL
Network
|
-
|
-
|
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37340
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
9.8 |
CRITICAL
Network
|
-
|
-
|
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37339
|
2026-04-18 12:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
6.8 |
MEDIUM
Network
|
-
|
-
|
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versio…
New
|
CWE-200
Information Exposure
|
CVE-2026-40490
|
2026-04-18 11:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
- |
|
-
|
-
|
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in ec_glob() that allo…
New
|
CWE-121 CWE-787
Stack-based Buffer Overflow Out-of-bounds Write
|
CVE-2026-40489
|
2026-04-18 11:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
8.9 |
HIGH
Network
|
-
|
-
|
Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to t…
New
|
CWE-79 CWE-345 CWE-434
Cross-site Scripting Insufficient Verification of Data Authenticity Unrestricted Upload of File with Dangerous Type
|
CVE-2026-40487
|
2026-04-18 11:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
8.8 |
HIGH
Local
|
-
|
-
|
Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /b…
New
|
CWE-78 CWE-116
OS Command Improper Encoding or Escaping of Output
|
CVE-2026-35582
|
2026-04-18 11:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|