π¨ CVE-2026-16334
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
π@cveNotify
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
π@cveNotify
GitHub
itsourcecode Hospital Management System V1.0 SQL Injection Vulnerability Β· Issue #1 Β· LiamJim/cve
itsourcecode Hospital Management System V1.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Hospital Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/ho...
π¨ CVE-2026-63729
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
π@cveNotify
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
π@cveNotify
Fatihβs Blog
Use-After-Free in SyncTeX Parser
Analysis of a Heap Use-After-Free vulnerability discovered in the SyncTeX parser.
π¨ CVE-2026-6952
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
π@cveNotify
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
π@cveNotify
Zyxel
Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wirelessβ¦
CVE: CVE-2026-6952 Summary Zyxel has released patches for specific firmware versions of its DSL/Ethernet CPE, fiber ONTs, and Wireless Extenders. These updates address the command injection vulnerability. Users are strongly advised to install the patchesβ¦
π¨ CVE-2026-50427
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50428
Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
π@cveNotify
Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-50430
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
π@cveNotify
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-50431
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
π@cveNotify
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
π@cveNotify
π¨ CVE-2026-50432
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
π@cveNotify
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-50433
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50434
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
π@cveNotify
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-50435
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
π@cveNotify
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50479
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
π@cveNotify
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50480
Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50482
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
π@cveNotify
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-50483
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.
π@cveNotify
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-9804
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
π@cveNotify
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
π@cveNotify
π¨ CVE-2026-58016
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
π@cveNotify
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
π@cveNotify
π¨ CVE-2026-50437
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
π@cveNotify
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-50438
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
π@cveNotify
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50439
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
π@cveNotify
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-50440
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.
π@cveNotify