Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · fabian

fabian

· 6 Critical

Total CVEs

484

Critical

6

Products

97

Search All CVEs →

484

Products (97)

simple online hotel reservation system18 CVEsonline music site18 CVEse-commerce website17 CVEsreal estate property management system16 CVEsclient details system16 CVEsonline hotel reservation system16 CVEsblood bank management system14 CVEssimple food ordering system14 CVEsonline product reservation system13 CVEsonline bidding system13 CVEsstudent file management system13 CVEsrefugee food management system12 CVEsonline reviewer system12 CVEsonline class and exam scheduling system12 CVEsresponsive hotel site11 CVEschat system10 CVEsvoting system10 CVEsonline ordering system10 CVEshostel management system9 CVEsschool fees payment system9 CVEshospital management system9 CVEspayroll management system8 CVEssimple forum8 CVEsstudent information system8 CVEssimple car rental system7 CVEsnero social networking site7 CVEssimple scheduling system7 CVEsscholars tracking system6 CVEssimple shopping cart6 CVEsautomated voting system6 CVEsonline complaint site6 CVEssimple grading system6 CVEsresponsive blog site5 CVEsmobile shop management system5 CVEslibrary management system5 CVEssimple cafe ordering system5 CVEshuman resource integrated system4 CVEsmedical store management system4 CVEse-commerce site4 CVEsonline examination system4 CVEscurrency exchange system4 CVEsonline job search engine4 CVEsonline faculty clearance system3 CVEsfood distributor site3 CVEshotel reservation system3 CVEsemployee record system3 CVEssimple blood donor management system3 CVEspublic chat room3 CVEssimple e-banking system3 CVEsproject monitoring system3 CVEsonline quiz site3 CVEsproduct inventory system3 CVEsdocument management system3 CVEstourism management system3 CVEsjob portal3 CVEsweb-based inventory and pos system2 CVEsblog site2 CVEsclass and exam timetable management system2 CVEscontact management system2 CVEsonline bike rental system2 CVEsonline book shop2 CVEsonline bus reservation site2 CVEsonline bus reservation system2 CVEsonline car rental system2 CVEsonline course registration site2 CVEsonline student management system2 CVEstrain ticket reservation system2 CVEsschool billing system1 CVEspolice station management system1 CVEsshopping portal1 CVEssimple attendance record system1 CVEspersonal diary management system1 CVEssimple bus reservation system1 CVEsonline ticket reservation system1 CVEsonline shopping store1 CVEssimple college management system1 CVEsonline polling1 CVEsonline notice board1 CVEsonline application system for admission1 CVEsjewellery store management system1 CVEssimple hospital management system1 CVEssimple movie ticket booking system1 CVEsemail logging interface1 CVEssimple photo gallery1 CVEseblog site1 CVEsdepartmental store management system1 CVEsclothing store management system1 CVEsstudent information management system1 CVEschamber of commerce membership management system1 CVEsstudent transcript processing system1 CVEstheater seat booking system1 CVEsbus reservation system1 CVEsalbum management system1 CVEstravel management system1 CVEsatm banking1 CVEswater billing system1 CVEsrestaurant order system1 CVEs

Recent Vulnerabilities

View all 484
CVE-2026-2912HIGH 7.3

A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation of the argument test_id results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

CVE-2025-70152CRITICAL 9.8

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.

CVE-2025-70151HIGH 8.8

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file type or extension. By uploading a PHP file and then requesting it from /uploads/, an attacker can execute arbitrary PHP code as the web server user.

CVE-2026-2224LOW 3.5

A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.

CVE-2026-2223HIGH 7.3

A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-2222LOW 2.4

A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

CVE-2026-2221HIGH 7.3

A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-2220HIGH 7.3

A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation of the argument difficulty_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

CVE-2026-2214LOW 2.4

A weakness has been identified in code-projects for Plugin 1.0. This affects an unknown part of the file /Administrator/PHP/AdminAddAlbum.php. This manipulation of the argument txtalbum causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-2213MEDIUM 4.7

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

CVE-2026-2212HIGH 7.3

A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Administrator/PHP/AdminEditCategory.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

CVE-2026-2211HIGH 7.3

A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCategory.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-2199HIGH 7.3

A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-2198HIGH 7.3

A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVE-2026-2197HIGH 7.3

A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-2196HIGH 7.3

A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

CVE-2026-2195HIGH 7.3

A vulnerability has been found in code-projects Online Reviewer System 1.0. This vulnerability affects unknown code of the file /system/system/admins/assessments/pretest/questions-view.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-2176MEDIUM 6.3

A security vulnerability has been detected in code-projects Contact Management System 1.0. This issue affects some unknown processing of the file index.py. Such manipulation of the argument selecteditem[0] leads to sql injection. The attack can be executed remotely.

CVE-2026-2174HIGH 7.3

A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely.

CVE-2026-2173HIGH 7.3

A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely.

CVE-2026-2172HIGH 7.3

A vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the component Login Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-2171HIGH 7.3

A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argument username/password results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

CVE-2026-2166HIGH 7.3

A security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-2156LOW 2.4

A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown function of the file /admin/announcement/index.php?view=add of the component Announcement Management Module. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-2133HIGH 7.3

A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCategory.php. This manipulation of the argument txtimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.