CVE-2026-37345Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-16); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-16: 2Mentions · 2026-04-17: 2Mentions · 2026-04-27: 1Active Exploitation · 2026-04-16: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 2Technical Details · 2026-04-27: 104-1604-1704-27
Signal classification3 categories
Disclosure
360.0%
Active Exploitation
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-162
Active Exploitation1Disclosure1
2026-04-172
Disclosure2
2026-04-271
Patch1
Full discourse5 posts
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-6443 | CVSS 9.8 🔴 CVE-2026-37345 | CVSS 9.8 🔴 CVE-2026-31843 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post announces three high‑severity CVEs (all with CVSS 9.8) and links to a CVE watch site, but does not provide details on exploitation, patches, or technical aspects beyond the score.

    0001054
    5.6K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-37345 | CVSS 9.8 SourceCodester Vehicle Parking Area Management System v1.0 - SQL Injection in /parking/manage_park[.]php Network exploitable, no authentication required. Immediate patching required. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/GPk1AyORa9

    Post summary

    The tweet highlights a critical SQL injection vulnerability in SourceCodester's Vehicle Parking Area Management System, warns it is network‑exploitable without authentication, and urges immediate patching.

    0000034
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-37345 SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. https://www.cve.org/CVERecord?id=CVE-2026-37345

    Post summary

    The post announces a new SQL Injection vulnerability in SourceCodester Vehicle Parking Area Management System v1.0, detailing the affected file but providing no PoC, exploit, patch, or evidence of active exploitation.

    0000073
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-37345 SQL Injection in SourceCodester Vehicle Parking Area Management System v1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-37345

    Post summary

    A new SQL Injection vulnerability (CVE-2026-37345) has been reported for SourceCodester Vehicle Parking Area Management System v1.0, with details available on a vulnerability database.

    0000043
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    🚨 CRITICAL — CVE-2026-37345 SourceCodester Vehicle Parking Area Management System v1.0 … CVSS 9.8 ⚡ Exploit in the wild 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-37345 #HP #CyberSecurity #InfoSec

    Post summary

    CVE-2026-37345, a critical vulnerability in SourceCodester Vehicle Parking Area Management System v1.0 with a CVSS score of 9.8, is actively being exploited in the wild and currently lacks a patch.

    000001
    145 followersView on X

Explore more