5.3

CVSS4.0

CVE-2026-5557 - badlogic pi-mono pi-mom Slack Bot slack.ts authentication bypass

A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file packages/mom/src/slack.ts of the component pi-mom Slack Bot. The manipulation results in authentication bypass using alternate channel. The attack can be executed remotely. The expl…

πŸ“… Published: April 5, 2026, 9:45 a.m. πŸ”„ Last Modified: April 24, 2026, 6:14 p.m.

5.3

CVSS4.0

CVE-2026-5556 - badlogic pi-mono loader.ts discoverAndLoadExtensions code injection

A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function discoverAndLoadExtensions of the file packages/coding-agent/src/core/extensions/loader.ts. The manipulation leads to code injection. Remote exploitation of the attack is possible. Th…

πŸ“… Published: April 5, 2026, 9:30 a.m. πŸ”„ Last Modified: April 24, 2026, 6:14 p.m.

6.9

CVSS4.0

CVE-2026-5555 - code-projects Concert Ticket Reservation System Parameter login.php sql injection

A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack m…

πŸ“… Published: April 5, 2026, 9:15 a.m. πŸ”„ Last Modified: April 24, 2026, 6:14 p.m.

6.9

CVSS4.0

CVE-2026-5554 - code-projects Concert Ticket Reservation System Parameter process_search.php sql injection

A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument search…

πŸ“… Published: April 5, 2026, 9 a.m. πŸ”„ Last Modified: April 24, 2026, 6:14 p.m.

5.3

CVSS4.0

CVE-2026-5553 - itsourcecode Online Cellphone System Parameter available.php sql injection

A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely…

πŸ“… Published: April 5, 2026, 8:45 a.m. πŸ”„ Last Modified: April 24, 2026, 6:14 p.m.

5.3

CVSS4.0

CVE-2026-5552 - PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. Th…

πŸ“… Published: April 5, 2026, 8:30 a.m. πŸ”„ Last Modified: April 24, 2026, 6:14 p.m.

6.9

CVSS4.0

CVE-2026-5551 - itsourcecode Free Hotel Reservation System Parameter login.php sql injection

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. The manipulation of the argument email results in sql injection. The attack may be launched remotely.…

πŸ“… Published: April 5, 2026, 8:15 a.m. πŸ”„ Last Modified: April 24, 2026, 6:14 p.m.

8.7

CVSS4.0

CVE-2026-5550 - Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.

πŸ“… Published: April 5, 2026, 8 a.m. πŸ”„ Last Modified: April 29, 2026, 11:44 p.m.

6.9

CVSS4.0

CVE-2026-5549 - Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key

A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The at…

πŸ“… Published: April 5, 2026, 7:45 a.m. πŸ”„ Last Modified: April 29, 2026, 11:41 p.m.

8.7

CVSS4.0

CVE-2026-5548 - Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.

πŸ“… Published: April 5, 2026, 7:30 a.m. πŸ”„ Last Modified: April 30, 2026, 1:39 p.m.
Total resulsts: 349182
Page 686 of 34,919
Β« previous page Β» next page
Filters