|
1551
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=login2. This manipulation of the argument ema…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5180
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1552
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha encontrado una falla en SourceCodester Simple Doctors Appointment System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /admin/ajax.PHP?action=login2. Esta manipulación del argu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5180
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1553
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_ca…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5181
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1554
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en SourceCodester Simple Doctors Appointment System hasta 1.0. Este problema afecta a algún procesamiento desconocido del archivo /doctors_appointment/admin/ajax…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5181
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1555
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insuffic…
|
CWE-80
Basic XSS
|
CVE-2026-1834
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1556
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Ibtana – WordPress Website Builder para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'ive' del plugin en todas las versiones hasta la 1.2.5.7, inclusive,…
|
CWE-80
Basic XSS
|
CVE-2026-1834
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1557
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.84. This is due to missing nonce validation on the 'aps_options_page' …
|
CWE-79
Cross-site Scripting
|
CVE-2026-1877
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1558
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Auto Post Scheduler para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta e incluyendo la 1.84. Esto se debe a la falta de validación d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1877
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1559
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Teacher Record System 1.0. Impacted is an unknown function of the file Teacher Record System of the component Parameter Handler. Performing a manipulation …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5182
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1560
|
7.3 |
HIGH
Network
|
-
|
-
|
Se encontró una vulnerabilidad en SourceCodester Teacher Record System 1.0. Afecta a una función desconocida del archivo Teacher Record System del componente Gestor de Parámetros. Realizar una manipu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5182
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|