5.3

CVSS4.0

CVE-2026-5559 - AntaresMugisho PyBlade AST Validation sandbox.py _is_safe_ast special elements used in a template e…

A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the file sandbox.py of the component AST Validation. Such manipulation leads to improper neutralization of special elements used in a template engine. The attack ma…

πŸ“… Published: April 5, 2026, 10:15 a.m. πŸ”„ Last Modified: April 5, 2026, 10:15 a.m.

5.3

CVSS4.0

CVE-2026-5558 - PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection

A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. …

πŸ“… Published: April 5, 2026, 10 a.m. πŸ”„ Last Modified: April 5, 2026, 10:16 a.m.

5.3

CVSS4.0

CVE-2026-5557 - badlogic pi-mono pi-mom Slack Bot slack.ts authentication bypass

A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file packages/mom/src/slack.ts of the component pi-mom Slack Bot. The manipulation results in authentication bypass using alternate channel. The attack can be executed remotely. The expl…

πŸ“… Published: April 5, 2026, 9:45 a.m. πŸ”„ Last Modified: April 5, 2026, 10:16 a.m.

5.3

CVSS4.0

CVE-2026-5556 - badlogic pi-mono loader.ts discoverAndLoadExtensions code injection

A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function discoverAndLoadExtensions of the file packages/coding-agent/src/core/extensions/loader.ts. The manipulation leads to code injection. Remote exploitation of the attack is possible. Th…

πŸ“… Published: April 5, 2026, 9:30 a.m. πŸ”„ Last Modified: April 5, 2026, 9:30 a.m.

6.9

CVSS4.0

CVE-2026-5555 - code-projects Concert Ticket Reservation System Parameter login.php sql injection

A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack m…

πŸ“… Published: April 5, 2026, 9:15 a.m. πŸ”„ Last Modified: April 5, 2026, 9:15 a.m.

6.9

CVSS4.0

CVE-2026-5554 - code-projects Concert Ticket Reservation System Parameter process_search.php sql injection

A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument search…

πŸ“… Published: April 5, 2026, 9 a.m. πŸ”„ Last Modified: April 5, 2026, 9 a.m.

5.3

CVSS4.0

CVE-2026-5553 - itsourcecode Online Cellphone System Parameter available.php sql injection

A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely…

πŸ“… Published: April 5, 2026, 8:45 a.m. πŸ”„ Last Modified: April 5, 2026, 9:16 a.m.

5.3

CVSS4.0

CVE-2026-5552 - PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. Th…

πŸ“… Published: April 5, 2026, 8:30 a.m. πŸ”„ Last Modified: April 5, 2026, 9:16 a.m.

6.9

CVSS4.0

CVE-2026-5551 - itsourcecode Free Hotel Reservation System Parameter login.php sql injection

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. The manipulation of the argument email results in sql injection. The attack may be launched remotely.…

πŸ“… Published: April 5, 2026, 8:15 a.m. πŸ”„ Last Modified: April 5, 2026, 8:15 a.m.

8.7

CVSS4.0

CVE-2026-5550 - Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.

πŸ“… Published: April 5, 2026, 8 a.m. πŸ”„ Last Modified: April 5, 2026, 8:16 a.m.
Total resulsts: 342297
Page 2 of 34,230
Β« previous page Β» next page
Filters