π¨ CVE-2026-49491
Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.
π@cveNotify
Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.
π@cveNotify
packetstorm.news
Packet Storm Security
Packet Storm Security provides security news, exploits, advisories, and tools for information security professionals.
π¨ CVE-2019-25718
DrΓ€ger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.
π@cveNotify
DrΓ€ger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.
π@cveNotify
π¨ CVE-2025-59601
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
π@cveNotify
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
π@cveNotify
π¨ CVE-2025-59604
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
π@cveNotify
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
π@cveNotify
π¨ CVE-2025-59605
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
π@cveNotify
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
π@cveNotify
π¨ CVE-2025-59606
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
π@cveNotify
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
π@cveNotify
π¨ CVE-2025-59609
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
π@cveNotify
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
π@cveNotify
π¨ CVE-2025-59610
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
π@cveNotify
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
π@cveNotify
π¨ CVE-2025-59611
Memory corruption in diagnostic services due to absence of input validation
π@cveNotify
Memory corruption in diagnostic services due to absence of input validation
π@cveNotify
π¨ CVE-2025-59612
Memory corruption in windows drivers while sending incorrect trusted application request
π@cveNotify
Memory corruption in windows drivers while sending incorrect trusted application request
π@cveNotify
π¨ CVE-2025-59613
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
π@cveNotify
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
π@cveNotify
π¨ CVE-2025-59614
Memory Corruption when sending random number generator command with insufficient output buffer size.
π@cveNotify
Memory Corruption when sending random number generator command with insufficient output buffer size.
π@cveNotify
π¨ CVE-2026-10296
A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
π@cveNotify
A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
π@cveNotify
GitHub
itsourcecode Fees Management System V1.0 SQL Injection Vulnerability Β· Issue #7 Β· ltranquility/vuln_submit
itsourcecode Fees Management System V1.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Fees Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/fees-manag...
π¨ CVE-2026-10297
A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
π@cveNotify
A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
π@cveNotify
GitHub
itsourcecode Fees Management System V1.0 SQL Injection Vulnerability Β· Issue #8 Β· ltranquility/vuln_submit
itsourcecode Fees Management System V1.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Fees Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/fees-manag...
π¨ CVE-2026-10298
A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2. This vulnerability affects the function whisper_model_load of the file ggml/src/ggml.c. The manipulation results in null pointer dereference. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2. This vulnerability affects the function whisper_model_load of the file ggml/src/ggml.c. The manipulation results in null pointer dereference. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - ggml-org/whisper.cpp: Port of OpenAI's Whisper model in C/C++
Port of OpenAI's Whisper model in C/C++. Contribute to ggml-org/whisper.cpp development by creating an account on GitHub.
π¨ CVE-2026-10299
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
π@cveNotify
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
π@cveNotify
π¨ CVE-2026-10300
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
π@cveNotify
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
π@cveNotify
GitHub
[Bug] Scheduler crash in LoRA, loss of availability Β· Issue #23141 Β· sgl-project/sglang
Checklist I searched related issues but found no solution. The bug persists in the latest version. Issues without environment info and a minimal reproducible demo are hard to resolve and may receiv...
π¨ CVE-2026-24085
Memory Corruption when processing display command line information due to improper initialization of a variable.
π@cveNotify
Memory Corruption when processing display command line information due to improper initialization of a variable.
π@cveNotify
π¨ CVE-2026-24088
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
π@cveNotify
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
π@cveNotify
π¨ CVE-2026-24089
Memory corruption while processing fastboot commands with invalid input.
π@cveNotify
Memory corruption while processing fastboot commands with invalid input.
π@cveNotify