最新预警列表

HIGH NVD Recent 2026-07-06

CVE-2026-12746:Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The

Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges t

HIGH NVD Recent 2026-07-06

CVE-2026-12740:Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 bu

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the

MEDIUM NVD Recent 2026-07-06

CVE-2026-14770:A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_room.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack

MEDIUM NVD Recent 2026-07-06

CVE-2026-14763:A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /

A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attac

MEDIUM NVD Recent 2026-07-06

CVE-2026-14640:A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the f

A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. Remote exploitation

LOW NVD Recent 2026-07-06

CVE-2026-14638:A flaw has been found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /pati

A flaw has been found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /patient.php. This manipulation of the argument editid causes sql injection. The attack may be initiated remotely. The exploit has been publ

LOW NVD Recent 2026-07-06

CVE-2026-14634:A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e0139

A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subs

LOW NVD Recent 2026-07-06

CVE-2026-14609:A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requir

MEDIUM NVD Recent 2026-07-06

CVE-2026-28385:In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import funct

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /im

MEDIUM NVD Recent 2026-07-06

CVE-2026-59511:Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrie

Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.

MEDIUM NVD Recent 2026-07-06

CVE-2026-14772:A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The impacted element is an

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The impacted element is an unknown function of the file /edit_course1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiate

MEDIUM NVD Recent 2026-07-06

CVE-2026-14771:A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The affected element is an unknown

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The affected element is an unknown function of the file /edit_exam1.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch t

MEDIUM NVD Recent 2026-07-06

CVE-2026-14768:A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the

A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc causes sql injection. The attack is possible to be carried out remotely. T

LOW NVD Recent 2026-07-06

CVE-2026-14767:A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecomme

A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sq

LOW NVD Recent 2026-07-06

CVE-2026-14766:A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unkn

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. The manipulation of the arg

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。