๐จ CVE-2026-10299
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
๐@cveNotify
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
๐@cveNotify
๐จ CVE-2026-10300
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
๐@cveNotify
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
๐@cveNotify
GitHub
[Bug] Scheduler crash in LoRA, loss of availability ยท Issue #23141 ยท sgl-project/sglang
Checklist I searched related issues but found no solution. The bug persists in the latest version. Issues without environment info and a minimal reproducible demo are hard to resolve and may receiv...
๐จ CVE-2026-24085
Memory Corruption when processing display command line information due to improper initialization of a variable.
๐@cveNotify
Memory Corruption when processing display command line information due to improper initialization of a variable.
๐@cveNotify
๐จ CVE-2026-24088
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
๐@cveNotify
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
๐@cveNotify
๐จ CVE-2026-24089
Memory corruption while processing fastboot commands with invalid input.
๐@cveNotify
Memory corruption while processing fastboot commands with invalid input.
๐@cveNotify
๐จ CVE-2026-24090
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
๐@cveNotify
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
๐@cveNotify
๐จ CVE-2026-24091
Memory corruption while processing fastboot commands with improperly formatted input.
๐@cveNotify
Memory corruption while processing fastboot commands with improperly formatted input.
๐@cveNotify
๐จ CVE-2026-24092
Memory Corruption when processing fastboot commands to set display mode.
๐@cveNotify
Memory Corruption when processing fastboot commands to set display mode.
๐@cveNotify
๐จ CVE-2026-54117
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
๐@cveNotify
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-54118
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
๐@cveNotify
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-47295
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-54116
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
๐@cveNotify
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
๐@cveNotify
๐จ CVE-2026-55010
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2025-24259
This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
๐@cveNotify
This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
๐@cveNotify
Apple Support
About the security content of macOS Sequoia 15.4 - Apple Support
This document describes the security content of macOS Sequoia 15.4.
๐จ CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-50468
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
๐@cveNotify
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
๐@cveNotify
๐จ CVE-2026-56176
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-58535
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
๐จ CVE-2026-58536
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-58537
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
๐@cveNotify