|
401
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulatio…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9451
|
2026-05-25 20:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
402
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql inje…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9450
|
2026-05-25 20:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
403
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possibl…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9449
|
2026-05-25 20:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
404
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the file /applyleave.php. Executing a manipulation of the argument ID can lead to c…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9448
|
2026-05-25 20:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
405
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Na…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9447
|
2026-05-25 20:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
406
|
- |
|
-
|
-
|
OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions perf…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-40127
|
2026-05-25 20:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
407
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argume…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9446
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
408
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulati…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-9445
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
409
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler.…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9444
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
410
|
8.8 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The…
New
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-9443
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|