Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,032
Critical923
High3,046
Medium10,863
Reset
Showing 2461-2480 of 15032 records
Threat Entry Updated 2026-01-09

CVE-2026-0592 - Online Product Reservation System Plugin

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This affects an unknown function of the file /handgunner-administrator/register_code.php of the component User Registration Handler. Performing a manipulation of the argument fname/lname/address/city/province/country/zip/tel_no/email/username results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

PLUGIN Online Product Reservation System

CVE-2026-0592

MEDIUM CVSS 6.9 2026-01-05
Threat Entry Updated 2026-01-09

CVE-2026-0591 - Online Product Reservation System Plugin

A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknown function of the file /app/checkout/update.php of the component Cart Update Handler. Such manipulation of the argument id/qty leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

PLUGIN Online Product Reservation System

CVE-2026-0591

MEDIUM CVSS 5.3 2026-01-05
Threat Entry Updated 2026-01-09

CVE-2026-0589 - Online Product Reservation System Plugin

A vulnerability was found in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the component Administration Backend. The manipulation results in improper authentication. The attack may be performed from remote. The exploit has been made public and could be used.

PLUGIN Online Product Reservation System

CVE-2026-0589

MEDIUM CVSS 6.9 2026-01-05
Threat Entry Updated 2026-01-09

CVE-2026-0590 - Online Product Reservation System Plugin

A vulnerability was determined in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file /app/checkout/delete.php of the component POST Parameter Handler. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

PLUGIN Online Product Reservation System

CVE-2026-0590

MEDIUM CVSS 5.3 2026-01-05
Threat Entry Updated 2026-01-22

CVE-2026-0588 - Rainrock RockOA Plugin

A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functionality of the file rockfun.php of the component API. This manipulation of the argument callback causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PLUGIN Rainrock RockOA

CVE-2026-0588

MEDIUM CVSS 5.1 2026-01-05
Threat Entry Updated 2026-01-09

CVE-2026-0586 - Online Product Reservation System Plugin

A vulnerability was detected in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file handgunner-administrator/prod.php. Performing a manipulation of the argument cat results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

PLUGIN Online Product Reservation System

CVE-2026-0586

MEDIUM CVSS 5.3 2026-01-05
Threat Entry Updated 2026-01-22

CVE-2026-0587 - Rainrock RockOA Plugin

A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file rock_page_gong.php of the component Cover Image Handler. The manipulation of the argument fengmian results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PLUGIN Rainrock RockOA

CVE-2026-0587

MEDIUM CVSS 5.1 2026-01-05
Threat Entry Updated 2026-01-09

CVE-2026-0585 - Online Product Reservation System Plugin

A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the file /order_view.php of the component GET Parameter Handler. Such manipulation of the argument transaction_id leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

PLUGIN Online Product Reservation System

CVE-2026-0585

MEDIUM CVSS 6.9 2026-01-05
Threat Entry Updated 2026-01-09

CVE-2026-0583 - Online Product Reservation System Plugin

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/user/login.php of the component User Login. The manipulation of the argument emailadd results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

PLUGIN Online Product Reservation System

CVE-2026-0583

MEDIUM CVSS 6.9 2026-01-05
Threat Entry Updated 2026-01-09

CVE-2026-0584 - Online Product Reservation System Plugin

A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

PLUGIN Online Product Reservation System

CVE-2026-0584

MEDIUM CVSS 5.3 2026-01-05
Threat Entry Updated 2026-01-22

CVE-2026-0582 - Society Management System Plugin

A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_activity_query.php. The manipulation of the argument Title leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

PLUGIN Society Management System

CVE-2026-0582

MEDIUM CVSS 5.3 2026-01-05
Threat Entry Updated 2026-01-12

CVE-2026-0581 - AC1206 Plugin

A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PLUGIN AC1206

CVE-2026-0581

MEDIUM CVSS 5.3 2026-01-05
Threat Entry Updated 2026-01-22

CVE-2026-0580 - API Key Manager App Plugin

A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Import Key Handler. Performing a manipulation results in cross site scripting. The attack can be initiated remotely.

PLUGIN API Key Manager App

CVE-2026-0580

MEDIUM CVSS 5.1 2026-01-05
Threat Entry Updated 2026-01-08

CVE-2025-9543 - Before 3 Plugin

The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 3

CVE-2025-9543

LOW CVSS 3.5 2026-01-05
Threat Entry Updated 2026-01-08

CVE-2025-14124 - Before 5 Plugin

The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

PLUGIN Before 5

CVE-2025-14124

HIGH CVSS 8.6 2026-01-05
Threat Entry Updated 2026-01-09

CVE-2026-0579 - Online Product Reservation System Plugin

A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the file /handgunner-administrator/edit.php of the component POST Parameter Handler. The manipulation of the argument prod_id/name/price/model/serial results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

PLUGIN Online Product Reservation System

CVE-2026-0579

MEDIUM CVSS 6.9 2026-01-04
Threat Entry Updated 2026-01-09

CVE-2026-0578 - Online Product Reservation System Plugin

A vulnerability has been found in code-projects Online Product Reservation System 1.0. Affected by this issue is some unknown functionality of the file /handgunner-administrator/delete.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PLUGIN Online Product Reservation System

CVE-2026-0578

MEDIUM CVSS 6.9 2026-01-04
Threat Entry Updated 2026-02-23

CVE-2026-0577 - Online Product Reservation System Plugin

A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /handgunner-administrator/prod.php. Executing a manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used.

PLUGIN Online Product Reservation System

CVE-2026-0577

MEDIUM CVSS 5.3 2026-01-04
Threat Entry Updated 2026-02-23

CVE-2026-0576 - Online Product Reservation System Plugin

A vulnerability was detected in code-projects Online Product Reservation System 1.0. Affected is an unknown function of the file /handgunner-administrator/prod.php of the component Parameter Handler. Performing a manipulation of the argument cat/price/name/model/serial results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

PLUGIN Online Product Reservation System

CVE-2026-0576

MEDIUM CVSS 6.9 2026-01-04
Threat Entry Updated 2026-01-09

CVE-2026-0575 - Online Product Reservation System Plugin

A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unknown function of the file /handgunner-administrator/adminlogin.php of the component Administrator Login. Such manipulation of the argument emailadd/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PLUGIN Online Product Reservation System

CVE-2026-0575

MEDIUM CVSS 6.9 2026-01-04
Scroll to top