Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/projectworlds/Car-Rental-System

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-5645 is a medium severity SQL injection vulnerability in projectworlds Car Rental System version 1.0. It affects an unknown functionality in the /pay.php file's Parameter Handler component, specifically via manipulation of the 'mpesa' argument. The vulnerability allows remote attackers to perform SQL injection. Although the exploit code is publicly available, there are no confirmed reports of exploitation in the wild. No official patch or remediation guidance has been provided yet.

Join the discussion

CVE-2026-5637 is a medium-severity SQL injection vulnerability in projectworlds Car Rental System version 1.0. The flaw exists in the /message_admin.php file within the Parameter Handler component, where manipulation of the Message argument can lead to SQL injection. This vulnerability can be exploited remotely without authentication. Although the exploit has been publicly disclosed, there are no known exploits in the wild at this time. No official patch or remediation guidance has been provided by the vendor yet.

Join the discussion

A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unknown code of the file /book_car.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Join the discussion

A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue affects some unknown processing of the file /signup.php. The manipulation of the argument fname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Join the discussion

A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_cars.php. The manipulation of the argument car_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Join the discussion

A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Join the discussion

A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add_cars.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Join the discussion

A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /message_admin.php. The manipulation of the argument Message leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/projectworlds/Car-Rental-System
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses