Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2026-36944

CVE-2026-36944_CVE-2026-36944

Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/admin/repairs/view_details.php.

n/a n/a n/a CVE
LOW 2.7 CVE-2026-36943

CVE-2026-36943_CVE-2026-36943

Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/repairs/manage_repair....

n/a n/a n/a CVE
LOW 2.7 CVE-2026-36942

CVE-2026-36942_CVE-2026-36942

Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php.

n/a n/a n/a CVE
LOW 2.7 CVE-2026-36941

CVE-2026-36941_CVE-2026-36941

Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php.

n/a n/a n/a CVE
LOW 2.7 CVE-2026-36938

CVE-2026-36938_CVE-2026-36938

Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php.

n/a n/a n/a CVE
LOW 2.7 CVE-2026-36937

CVE-2026-36937_CVE-2026-36937

Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php.

n/a n/a n/a CVE
LOW 1.7 CVE-2026-32270

Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments_CVE-2026-32270

Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay ...

craftcms commerce >= 4.0.0, < 4.11.0 CVE
LOW 3.5 CVE-2026-33659

EspoCRM: SSRF via DNS Rebinding in Attachment fromImageUrl Endpoint Allows Internal Network Access_CVE-2026-33659

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpo...

espocrm espocrm < 9.3.4 CVE
LOW 2.7 CVE-2026-39510

WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Insecure Direct Object References (IDOR) vulnerability_CVE-2026-39510

Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allow...

WP Chill Image Photo Gallery Final Tiles Grid CVE
LOW 2.1 CVE-2026-30812

Stored Cross-Site Scripting in Event Comments via Filter Bypass_CVE-2026-30812

Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects...

Pandora FMS Pandora FMS 777 CVE