5.3

CVSS4.0

CVE-2026-5640 - PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carrie…

πŸ“… Published: April 6, 2026, 9 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5639 - PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection

A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The expl…

πŸ“… Published: April 6, 2026, 8:45 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

3.7

CVSS3.1

CVE-2026-37977 - Keycloak: org.keycloak.protocol.oidc.grants.ciba: keycloak: information disclosure via cors header …

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp` claim from a client-supplied JSON Web Token (JWT) is used to set the `Access-C…

πŸ“… Published: April 6, 2026, 8:34 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5638 - HerikLyma CPPWebFramework path traversal

A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem ear…

πŸ“… Published: April 6, 2026, 8:30 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5637 - projectworlds Car Rental System Parameter message_admin.php sql injection

A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown code of the file /message_admin.php of the component Parameter Handler. Such manipulation of the argument Message leads to sql injection. The attack may be launched remotely. The ex…

πŸ“… Published: April 6, 2026, 8:15 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

0.0

CVE-2026-5664 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-30078. Reason: This candidate is a reservation duplicate of CVE-2026-30078. Notes: All CVE users should reference CVE-2026-30078 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: April 6, 2026, 8:06 a.m. πŸ”„ Last Modified: April 6, 2026, 3:17 p.m.

5.3

CVSS4.0

CVE-2026-5636 - PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection. The attack may be initiated remotely. The exploit has been made …

πŸ“… Published: April 6, 2026, 8 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5635 - PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection. The attack can be laun…

πŸ“… Published: April 6, 2026, 7:45 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5634 - projectworlds Car Rental Project Parameter book_car.php sql injection

A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /book_car.php of the component Parameter Handler. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The e…

πŸ“… Published: April 6, 2026, 7:30 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5633 - assafelovic gpt-researcher ws Endpoint server-side request forgery

A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been pu…

πŸ“… Published: April 6, 2026, 7 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 343975
Page 154 of 34,398
Β« previous page Β» next page
Filters