ZeroHour

Vulnerabilities

761 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-36946
+1 in the same advisory: …36947
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php.

Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php.

NVD description · AI analysis pending
2.7<1% PoC
  • oretnom23 computer and mobile repair shop management system
CVE-2026-36923
+1 in the same advisory: …36922
Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php.

Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php.

NVD description · AI analysis pending
2.7<1% PoC
  • oretnom23 cab management system
CVE-2026-30523
+1 in the same advisory: …30522
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation.

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the duration must be a positive integer. An attacker can submit a negative value for the months parameter. The system accepts this invalid data and creates a loan plan with a negative duration.

NVD description · AI analysis pending
6.5<1% PoC
  • oretnom23 loan management system
CVE-2026-30521
+1 in the same advisory: …30520
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation.

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific interest rates. While the frontend interface prevents users from entering negative numbers, this constraint is not enforced on the backend. An authenticated attacker can bypass the client-side restriction by manipulating the HTTP POST request to submit a negative value for the interest_percentage. This results in the creation of loan plans with negative interest rates.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • oretnom23 loan management system
CVE-2026-30530
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action).

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious SQL commands.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • oretnom23 online food ordering system
CVE-2026-3800
+2 in the same advisory: …3806 …3819
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0.

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.1
group max
<1% PoC
  • oretnom23 resort reservation system
CVE-2026-3771
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0.

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • oretnom23 resort reservation system
CVE-2026-3770
A flaw has been found in SourceCodester Computer Laboratory Management System 1.0.

A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • oretnom23 computer laboratory management system
CVE-2026-3752
+1 in the same advisory: …3751
A flaw has been found in SourceCodester Employee Task Management System up to 1.0.

A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

NVD description · AI analysis pending
2.0<1% PoC
  • oretnom23 employee task management system
CVE-2026-3746
A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0.

A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

NVD description · AI analysis pending
5.5<1% PoC ×2
  • oretnom23 simple responsive tourism website
CVE-2026-3702
A vulnerability was detected in SourceCodester Loan Management System 1.0.

A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • oretnom23 loan management system
CVE-2026-26892
+1 in the same advisory: …26891
Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.

NVD description · AI analysis pending
7.2
group max
<1% PoC
  • oretnom23 simple logistic hub parcel\'s management system
CVE-2026-26889
+3 in the same advisory: …26888 …26887 …26890
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.

NVD description · AI analysis pending
2.7<1% PoC
  • oretnom23 pharmacy point of sale system
CVE-2026-26886
+3 in the same advisory: …26885 …26884 …26883
Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_service.php.

Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_service.php.

NVD description · AI analysis pending
2.7<1% PoC
  • oretnom23 simple online men\'s salon management system
CVE-2026-26707
+4 in the same advisory: …26706 …26705 …26704 …26708
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.

NVD description · AI analysis pending
9.8<1% PoC
  • oretnom23 pharmacy point of sale system
CVE-2026-2848
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0.

A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

NVD description · AI analysis pending
5.5<1% PoC
  • oretnom23 simple responsive tourism website
CVE-2025-70141
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php.

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitive operations such as creating customers and deleting users (including the admin account), as well as modifying or deleting other application records (tickets, departments, comments), resulting in unauthorized data modification.

NVD description · AI analysis pending
9.4<1% PoC
  • oretnom23 customer support system
CVE-2026-2159
+1 in the same advisory: …2160
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0.

A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Executing a manipulation of the argument firstname/lastname/username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • oretnom23 simple responsive tourism website
CVE-2026-1745
A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0.

A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

NVD description · AI analysis pending
2.1<1% PoC ×2
  • oretnom23 medical certificate generator app
CVE-2025-14221
A vulnerability was detected in SourceCodester Online Banking System 1.0.

A vulnerability was detected in SourceCodester Online Banking System 1.0. This impacts an unknown function of the file /?page=user. The manipulation of the argument First Name/Last Name results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.

NVD description · AI analysis pending
2.0<1% PoC
  • oretnom23 banking system
CVE-2025-65881
Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php.

Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php.

NVD description · AI analysis pending
6.1<1% PoC ×2
  • oretnom23 zoo management system
CVE-2025-13468
A weakness has been identified in SourceCodester Alumni Management System 1.0.

A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the argument ID can lead to missing authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

NVD description · AI analysis pending
2.1<1% PoC
  • oretnom23 alumni management system
CVE-2025-13451
+2 in the same advisory: …13449 …13450
A vulnerability was identified in SourceCodester Online Shop Project 1.0.

A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

NVD description · AI analysis pending
5.5
group max
<1% PoC
  • oretnom23 online shop project