9.3

CVSS4.0

CVE-2026-3000 - Changing|IDExpert Windows Logon Agent - Remote Code Execution

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.

📅 Published: March 2, 2026, 6:03 a.m. 🔄 Last Modified: March 2, 2026, 2:08 p.m.

6.9

CVSS4.0

CVE-2026-3413 - itsourcecode University Management System admin_single_student.php sql injection

A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may…

📅 Published: March 2, 2026, 6:02 a.m. 🔄 Last Modified: March 2, 2026, 2:09 p.m.

9.3

CVSS4.0

CVE-2026-2999 - Changing|IDExpert Windows Logon Agent - Remote Code Execution

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

📅 Published: March 2, 2026, 5:59 a.m. 🔄 Last Modified: March 2, 2026, 2:09 p.m.

5.3

CVSS4.0

CVE-2026-3412 - itsourcecode University Management System att_single_view.php cross site scripting

A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file /att_single_view.php. The manipulation of the argument dt results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.

📅 Published: March 2, 2026, 5:32 a.m. 🔄 Last Modified: March 2, 2026, 2:11 p.m.

6.9

CVSS4.0

CVE-2026-3411 - itsourcecode University Management System admin_single_student_update.php sql injection

A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /admin_single_student_update.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. …

📅 Published: March 2, 2026, 5:02 a.m. 🔄 Last Modified: March 2, 2026, 2:31 p.m.

6.9

CVSS4.0

CVE-2026-3410 - itsourcecode Society Management System check_studid.php sql injection

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/check_studid.php. Executing a manipulation of the argument student_id can lead to sql injection. The attack may be launched remotely. The explo…

📅 Published: March 2, 2026, 4:32 a.m. 🔄 Last Modified: March 2, 2026, 3:01 p.m.

6.9

CVSS4.0

CVE-2026-3409 - eosphoros-ai db-gpt Flow Import Endpoint import importlib.machinery.SourceFileLoader.exec_module co…

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import Endpoint. Performing a manipulation as part of File results in code injection. The atta…

📅 Published: March 2, 2026, 4:02 a.m. 🔄 Last Modified: March 2, 2026, 3:04 p.m.

5.3

CVSS4.0

CVE-2026-3408 - Open Babel CDXML File atom.cpp GetExplicitValence null pointer dereference

A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit is publicly available a…

📅 Published: March 2, 2026, 3:32 a.m. 🔄 Last Modified: March 2, 2026, 2:39 p.m.

4.8

CVSS4.0

CVE-2026-3407 - YosysHQ yosys BLIF File rtlil.h set heap-based overflow

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has be…

📅 Published: March 2, 2026, 3:02 a.m. 🔄 Last Modified: March 2, 2026, 2:43 p.m.

6.9

CVSS4.0

CVE-2026-3406 - projectworlds Online Art Gallery Shop Registration registration.php sql injection

A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotel…

📅 Published: March 2, 2026, 2:32 a.m. 🔄 Last Modified: March 2, 2026, 2:55 p.m.
Total resulsts: 335484
Page 23 of 33,549
« previous page » next page
Filters