Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Windhxy

#16702of 56,330
17.3Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-69292
7.5
2026-08-09
Npm · Node-Sql-Query · CVE-2026-19351
**Name of the Vulnerable Software and Affected Versions** dresende node-sql-query versions 0.1.25 through 0.1.28 **Description** A SQL injection issue exists in the Request Parameter Handler component within the `lib/Select.js` library. The flaw is located in the `SelectQuery.from()` and `SelectQuery.build()` functions, allowing a remote attacker to perform a manipulation that results in the execution of arbitrary SQL commands. **Recommendations** Upgrade to version 0.1.29.
PT-2025-38411
9.8
2025-09-18
Itsourcecode · Student Information Management System · CVE-2025-10673
**Name of the Vulnerable Software and Affected Versions** itsourcecode Student Information Management System version 1.0 **Description** A vulnerability exists in itsourcecode Student Information Management System version 1.0. The issue is a SQL injection affecting an unknown function within the `/admin/modules/class/index.php` file. The `classId` argument can be manipulated to trigger the injection. This manipulation can be initiated remotely. The exploit has been publicly disclosed. **Recommendations** As a temporary workaround, consider restricting access to the `/admin/modules/class/index.php` file until a fix is available.