6.9

CVSS4.0

CVE-2026-5645 - projectworlds Car Rental System Parameter pay.php sql injection

A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.php of the component Parameter Handler. Executing a manipulation of the argument mpesa can lead to sql injection. The attack can be launched remotely. T…

πŸ“… Published: April 6, 2026, 10:15 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

4.8

CVSS4.0

CVE-2026-5644 - Cyber-III Student-Management-System batch-notice.php cross site scripting

A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /admin/Add%20notice/batch-notice.php. Performing a manipulation of the argument $_SERVER['PHP_SELF'] results in cross site scripting…

πŸ“… Published: April 6, 2026, 10 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

4.8

CVSS4.0

CVE-2026-5643 - Cyber-III Student-Management-System Admin Add Endpoint notice.php cross site scripting

A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admin/Add%20notice/notice.php of the component Admin Add Endpoint. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cros…

πŸ“… Published: April 6, 2026, 9:45 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5642 - Cyber-III Student-Management-System HTTP POST Request update.php improper authorization

A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown function of the file /viva/update.php of the component HTTP POST Request Handler. This manipulation of the argument Name causes improper authorization. It is…

πŸ“… Published: April 6, 2026, 9:30 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.6

CVSS3.1

CVE-2026-5673 - Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a t…

πŸ“… Published: April 6, 2026, 9:16 a.m. πŸ”„ Last Modified: May 1, 2026, 7:53 p.m.

5.3

CVSS4.0

CVE-2026-5641 - PHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injection

A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-image1.php of the component Parameter Handler. The manipulation of the argument filename results in sql injection. The attack may be performed from remot…

πŸ“… Published: April 6, 2026, 9:15 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5640 - PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carrie…

πŸ“… Published: April 6, 2026, 9 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5639 - PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection

A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The expl…

πŸ“… Published: April 6, 2026, 8:45 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

3.7

CVSS3.1

CVE-2026-37977 - Keycloak: org.keycloak.protocol.oidc.grants.ciba: keycloak: information disclosure via cors header …

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp` claim from a client-supplied JSON Web Token (JWT) is used to set the `Access-C…

πŸ“… Published: April 6, 2026, 8:34 a.m. πŸ”„ Last Modified: April 24, 2026, 3:44 p.m.

6.9

CVSS4.0

CVE-2026-5638 - HerikLyma CPPWebFramework path traversal

A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem ear…

πŸ“… Published: April 6, 2026, 8:30 a.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 349182
Page 670 of 34,919
Β« previous page Β» next page
Filters