|
1241
|
7.3 |
HIGH
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en itsourcecode Payroll Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /manage_user.php del componente…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5237
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1242
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.php of the component Parameter Handler. E…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5238
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1243
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Se identificó una vulnerabilidad en Axiomatic Bento4 hasta la versión 1.6.0-641. Se ve afectada la función AP4_BitReader::SkipBits del archivo Ap4Dac4Atom.cpp del componente DSI v1 Parser. Dicha mani…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5236
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1244
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and incl…
|
CWE-89
SQL Injection
|
CVE-2026-4668
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1245
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Booking for Appointments and Events Calendar - Amelia para WordPress es vulnerable a inyección SQL a través del parámetro `sort` en el endpoint de listado de pagos en todas las versiones ha…
|
CWE-89
SQL Injection
|
CVE-2026-4668
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1246
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha identificado una debilidad en itsourcecode Payroll Management System 1.0. Este problema afecta a alguna funcionalidad desconocida del archivo /view_employee.php del componente Gestor de Parámet…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5238
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1247
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5240
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1248
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en code-projects BloodBank Managing System 1.0. Esto afecta una parte desconocida del archivo /admin_state.php. La manipulación del argumento statena…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5240
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1249
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such man…
|
CWE-913 CWE-915
Improper Control of Dynamically-Managed Code Resources Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-5248
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1250
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in al…
|
CWE-862
Missing Authorization
|
CVE-2026-3831
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|