|
1871
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php.
|
CWE-89
SQL Injection
|
CVE-2026-37594
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1872
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.
|
CWE-89
SQL Injection
|
CVE-2026-37595
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1873
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php.
|
CWE-89
SQL Injection
|
CVE-2026-37596
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1874
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php.
|
CWE-89
SQL Injection
|
CVE-2026-37597
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1875
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings.
|
CWE-89
SQL Injection
|
CVE-2026-37598
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1876
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.
|
CWE-89
SQL Injection
|
CVE-2026-37600
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1877
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php.
|
CWE-89
SQL Injection
|
CVE-2026-37601
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1878
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php.
|
CWE-89
SQL Injection
|
CVE-2026-37602
|
2026-04-18 00:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1879
|
3.7 |
LOW
Network
|
-
|
-
|
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt password verification only when the supplied username exists, returning immediate…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-40263
|
2026-04-18 00:29 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1880
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID} is registered without authentication middleware,…
|
CWE-862
Missing Authorization
|
CVE-2026-40265
|
2026-04-18 00:29 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|