A vulnerability identified as critical has been detected in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Financial Report Page. The manipulation leads to improper authorization.
This vulnerability is referenced as CVE-2026-3738. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability categorized as critical has been discovered in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization.
The identification of this vulnerability is CVE-2026-3737. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulation of the argument from results in sql injection.
This vulnerability was named CVE-2026-3736. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulation of the argument from leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-3735. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of the argument manager_id causes improper authorization.
This vulnerability is handled as CVE-2026-3734. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in xuxueli xxl-job up to 3.3.2 and classified as critical. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-3733. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project maintainer closed the issue report with the following statement: "Access token security verification is required." (translated from Chinese)