Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · oretnom23

oretnom23

· 94 Critical

Total CVEs

761

Critical

94

Products

112

Search All CVEs →

761

Products (112)

online computer and laptop store32 CVEscomputer laboratory management system30 CVEsonline food ordering system29 CVEshuman resource management system29 CVEsonline eyewear shop29 CVEslost and found information system27 CVEsclinic\'s patient management system27 CVEscustomer support system19 CVEsfood ordering management system17 CVEssimple online bidding system17 CVEsac repair and services system16 CVEsservice provider management system15 CVEssimple customer relationship management system15 CVEsemployee task management system15 CVEsstudent study center desk management system15 CVEsemployee and visitor gate pass logging system15 CVEssimple student attendance system14 CVEsonline car wash booking system13 CVEssimple cold storage management system13 CVEscar driving school management system12 CVEssimple realtime quiz system12 CVEsestablishment billing management system11 CVEsstudent grading system11 CVEsonline mobile store management system9 CVEspharmacy point of sale system9 CVEslot reservation management system9 CVEstracking monitoring management system8 CVEsstock management system8 CVEssimple online men\'s salon management system8 CVEsschool fees management system7 CVEsonline medicine ordering system7 CVEsapartment visitor management system7 CVEssimple subscription website7 CVEsevent registration system7 CVEssimple company website7 CVEsonline id generator system7 CVEspackers and movers management system6 CVEsmedicine tracker system6 CVEsclinic queuing system6 CVEsmusic gallery site6 CVEsschool fees payment system6 CVEsonline bank management system6 CVEswarehouse management system5 CVEsraffle draw system5 CVEsrailway reservation system5 CVEsresort reservation system5 CVEslaundry shop management system5 CVEstoll tax management system5 CVEsloan management system5 CVEssimple responsive tourism website5 CVEsbanking system5 CVEscomplaints report management system5 CVEsonline birth certificate management system5 CVEscab management system5 CVEssimple forum\/discussion system4 CVEsbudget and expense tracker system4 CVEscashier queuing system4 CVEscosmetics and beauty product online store4 CVEsexpense management system4 CVEsfacebook news feed like4 CVEshouse rental management system4 CVEsschool log management system4 CVEstrain station ticketing system4 CVEsyoga class registration system4 CVEssimple barangay management system3 CVEsvehicle service management system3 CVEsjudging management system3 CVEsproduct show room site3 CVEstask reminder system3 CVEssurvey application system3 CVEsexpense tracker3 CVEsonline magazine management system3 CVEsonline learning system3 CVEssimple online book store system3 CVEsschool intramurals - student attendance management system3 CVEsonline shop project3 CVEssentiment based movie rating system3 CVEsonline flight booking management system3 CVEscomputer and mobile repair shop management system2 CVEsalumni management system2 CVEssimple cafe billing system2 CVEsmusic class enrollment system2 CVEssimple forum website2 CVEssimple image stack website2 CVEssimple invoice generator system2 CVEssimple logistic hub parcel\'s management system2 CVEssimple music cloud community system2 CVEsgym management system2 CVEselectric billing management system2 CVEselearning system2 CVEsbook store management system2 CVEsonline tutor portal2 CVEsonline veterinary appointment system2 CVEsonline student result system2 CVEsonline motorcycle \(bike\) rental system1 CVEsemployees payroll management system1 CVEszoo management system1 CVEspos - point of sale system1 CVEsearnings and expense tracker application1 CVEsonline diagnostic lab management system1 CVEspayroll management system1 CVEsmedical certificate generator app1 CVEsvisitor management system1 CVEsonline pizza ordering system1 CVEssimple inventory management system1 CVEstask management system1 CVEssimple library management system1 CVEspurchase order management system1 CVEsblog site1 CVEsonline exam system1 CVEsonline job portal1 CVEsblock inserter for dynamic content1 CVEs

Recent Vulnerabilities

View all 761
CVE-2026-36947LOW 2.7

Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/admin/services/view_service.php.

CVE-2026-36946LOW 2.7

Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php.

CVE-2026-36923LOW 2.7

Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php.

CVE-2026-36922LOW 2.7

Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category.php.

CVE-2026-30523MEDIUM 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the duration must be a positive integer. An attacker can submit a negative value for the months parameter. The system accepts this invalid data and creates a loan plan with a negative duration.

CVE-2026-30522MEDIUM 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific penalty rates for overdue payments. While the frontend interface prevents users from entering negative numbers in the "Monthly Overdue Penalty" field, this constraint is not enforced on the backend. An authenticated attacker can bypass the client-side restriction by manipulating the HTTP POST request to submit a negative value for the penalty_rate.

CVE-2026-30521MEDIUM 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific interest rates. While the frontend interface prevents users from entering negative numbers, this constraint is not enforced on the backend. An authenticated attacker can bypass the client-side restriction by manipulating the HTTP POST request to submit a negative value for the interest_percentage. This results in the creation of loan plans with negative interest rates.

CVE-2026-30520MEDIUM 5.4

A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input supplied to the "borrower_id" parameter in a POST request, allowing an authenticated attacker to inject malicious SQL commands.

CVE-2026-30534HIGH 8.3

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.

CVE-2026-30533CRITICAL 9.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.

CVE-2026-30532CRITICAL 9.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.

CVE-2026-30531HIGH 8.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker to inject malicious SQL commands.

CVE-2026-30530CRITICAL 9.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious SQL commands.

CVE-2026-30529HIGH 8.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker to inject malicious SQL commands.

CVE-2026-30527MEDIUM 5.4

A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or updating a category. When an administrator or user visits the Category list page (or any page where this category is rendered), the injected JavaScript executes immediately in their browser.

CVE-2026-3819LOW 3.5

A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown function of the file /?page=manage_reservation of the component Reservation Management Module. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-3806MEDIUM 6.3

A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown processing of the file /room_rates.php. This manipulation of the argument q causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-3800MEDIUM 6.3

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-3771MEDIUM 6.3

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVE-2026-3770MEDIUM 4.3

A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.

CVE-2026-3752MEDIUM 4.7

A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

CVE-2026-3751MEDIUM 4.7

A vulnerability was detected in SourceCodester Employee Task Management System 1.0. Impacted is an unknown function of the file /daily-attendance-report.php of the component GET Parameter Handler. The manipulation of the argument Date results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

CVE-2026-3746HIGH 7.3

A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-3702MEDIUM 4.3

A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVE-2026-26892HIGH 7.2

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.