8.1
CVE-2026-40960 - Crafted Module Enables Unauthorized Access to Insecure Environment in Luanti
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.
9.3
CVE-2026-40959 - Lua sandbox escape via crafted module in Luanti using LuaJIT
Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
8.7
CVE-2026-40502 - OpenHarness Remote Administrative Command Injection via Gateway Handler
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execuβ¦
7.1
CVE-2026-40503 - OpenHarness Path Traversal Information Disclosure via /memory show
OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memoβ¦
6.5
CVE-2026-37100 - Unauthenticated BLE Control Access on Yamaha SR-B30A Sound Bar
An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio range to connect without authentication via the Sound Bar Remote protocol
9.8
CVE-2026-37345 - SQL Injection in Vehicle Parking Area Management System v1.0
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.
0.0
CVE-2026-37342 - SQL Injection in SourceCodester Vehicle Parking Area Management System
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.
4.7
CVE-2026-37346 - SQL Injection in /payroll/view_account.php of SourceCodester Payroll Management System v1.0
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.
7.3
CVE-2026-37336 - SQL Injection in /music/view_music.php of Simple Music Cloud Community System
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.
0.0
CVE-2026-37340 - Simple Music Cloud Community System v1.0 β SQL Injection in /music/edit_music.php
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.