6.9

CVSS4.0

CVE-2026-3410 - itsourcecode Society Management System check_studid.php sql injection

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/check_studid.php. Executing a manipulation of the argument student_id can lead to sql injection. The attack may be launched remotely. The explo…

📅 Published: March 2, 2026, 4:32 a.m. 🔄 Last Modified: March 2, 2026, 3:01 p.m.

6.9

CVSS4.0

CVE-2026-3409 - eosphoros-ai db-gpt Flow Import Endpoint import importlib.machinery.SourceFileLoader.exec_module co…

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import Endpoint. Performing a manipulation as part of File results in code injection. The atta…

📅 Published: March 2, 2026, 4:02 a.m. 🔄 Last Modified: March 2, 2026, 3:04 p.m.

5.3

CVSS4.0

CVE-2026-3408 - Open Babel CDXML File atom.cpp GetExplicitValence null pointer dereference

A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit is publicly available a…

📅 Published: March 2, 2026, 3:32 a.m. 🔄 Last Modified: March 2, 2026, 2:39 p.m.

4.8

CVSS4.0

CVE-2026-3407 - YosysHQ yosys BLIF File rtlil.h set heap-based overflow

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has be…

📅 Published: March 2, 2026, 3:02 a.m. 🔄 Last Modified: March 2, 2026, 2:43 p.m.

6.9

CVSS4.0

CVE-2026-3406 - projectworlds Online Art Gallery Shop Registration registration.php sql injection

A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotel…

📅 Published: March 2, 2026, 2:32 a.m. 🔄 Last Modified: March 2, 2026, 2:55 p.m.

2.3

CVSS4.0

CVE-2026-3405 - thinkgem JeeSite Connection path traversal

A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitab…

📅 Published: March 2, 2026, 2:02 a.m. 🔄 Last Modified: March 2, 2026, 1:36 p.m.

2.3

CVSS4.0

CVE-2026-3404 - thinkgem JeeSite Endpoint CasOutHandler.java xml external entity reference

A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The attack may be performed from remote. Attacks of thi…

📅 Published: March 2, 2026, 1:32 a.m. 🔄 Last Modified: March 2, 2026, 3:17 p.m.

4.8

CVSS4.0

CVE-2026-3403 - PHPGurukul Student Record Management System edit-subject.php cross site scripting

A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The expl…

📅 Published: March 2, 2026, 1:02 a.m. 🔄 Last Modified: March 2, 2026, 1:02 a.m.

4.8

CVSS4.0

CVE-2026-3402 - PHPGurukul Student Record Management System edit-course.php cross site scripting

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The expl…

📅 Published: March 2, 2026, 12:32 a.m. 🔄 Last Modified: March 2, 2026, 12:32 a.m.

2.3

CVSS4.0

CVE-2026-3401 - SourceCodester Web-based Pharmacy Product Management System session expiration

A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitab…

📅 Published: March 2, 2026, 12:02 a.m. 🔄 Last Modified: March 2, 2026, 12:02 a.m.
Total resulsts: 335300
Page 7 of 33,530
« previous page » next page
Filters