π¨ CVE-2026-5533
A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
58ead8e7e02026014 Β· Issue #20 Β· August829/CVEP
CVE-2026-5533
π¨ CVE-2026-5534
A vulnerability was identified in itsourcecode Online Enrollment System 1.0. This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the component Parameter Handler. Such manipulation of the argument USERID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
π@cveNotify
A vulnerability was identified in itsourcecode Online Enrollment System 1.0. This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the component Parameter Handler. Such manipulation of the argument USERID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
π@cveNotify
GitHub
ldan42008-ux/cve
cve. Contribute to ldan42008-ux/cve development by creating an account on GitHub.
π¨ CVE-2026-5535
A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the argument dataSet results in path traversal. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the argument dataSet results in path traversal. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
Path Traversal via Untrusted MQTT Messages Leads to Directory Enumeration in Android Client Β· Issue #25 Β· AnalogyC0de/public_exp
Path Traversal via Untrusted MQTT Messages Leads to Directory Enumeration in Android Client Project Information Project: FedML Component: Android Training Client (fedmlsdk) Repository: https://gith...
π¨ CVE-2026-5536
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
Remote Code Execution via gRPC Pickle Deserialization in Fedml Β· Issue #26 Β· AnalogyC0de/public_exp
Remote Code Execution via gRPC Pickle Deserialization in Fedml Identification Project: Fedml Repository: https://github.com/FedML-AI/FedML Affected Version/Commit: <=0.8.9 CVE Description Fedml ...
π¨ CVE-2026-5537
A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the component HTTP GET Parameter Handler. The manipulation of the argument seid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the component HTTP GET Parameter Handler. The manipulation of the argument seid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
Vulnerability-Report/CourseSEL-SQLi at main Β· zy606/Vulnerability-Report
poc repository. Contribute to zy606/Vulnerability-Report development by creating an account on GitHub.
π¨ CVE-2026-5538
A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_url of the component judge_server_heartbeat Endpoint. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of the file JudgeServer.service_url of the component judge_server_heartbeat Endpoint. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
Stored SSRF in QingdaoU Onlinejudge Judge Server service_url Β· Issue #27 Β· AnalogyC0de/public_exp
Stored SSRF in Onlinejudge Judge Server service_url Identification Project: OnlineJudge Repository: https://github.com/QingdaoU/OnlineJudge Affected Version/Commit: <=v1.6.1 CVE Description A st...
π¨ CVE-2026-5539
A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember.php of the component Parameter Handler. This manipulation of the argument firstName causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
π@cveNotify
A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember.php of the component Parameter Handler. This manipulation of the argument firstName causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
π@cveNotify
π¨ CVE-2026-5590
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context data is passed to tcp_backlog_is_full() and dereferenced without validation, leading to a crash.
π@cveNotify
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context data is passed to tcp_backlog_is_full() and dereferenced without validation, leading to a crash.
π@cveNotify
GitHub
net: ip/tcp: Null pointer dereference can be triggered by a race condition
The `tcp_recv()` function in `subsys/net/ip/tcp.c` contains a null pointer dereference vulnerability that can be triggered by a race condition:
### Details
1. The protocol stack releases a T...
### Details
1. The protocol stack releases a T...
π¨ CVE-2026-5541
A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /modmemberinfo.php of the component Parameter Handler. Performing a manipulation of the argument userid results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
π@cveNotify
A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /modmemberinfo.php of the component Parameter Handler. Performing a manipulation of the argument userid results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
π@cveNotify
π¨ CVE-2026-5542
A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation of the argument userid can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
π@cveNotify
A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation of the argument userid can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
π@cveNotify
π¨ CVE-2026-5543
A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected element is an unknown function of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
π@cveNotify
A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected element is an unknown function of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
π@cveNotify
GitHub
phpgurukul User Registration & Login and User Management System With admin panel V3.3 /admin/yesterday-reg-users.php SQL injectionβ¦
phpgurukul User Registration & Login and User Management System With admin panel V3.3 /admin/yesterday-reg-users.php SQL injection NAME OF AFFECTED PRODUCT(S) User Registration & Login and ...
π¨ CVE-2026-5544
A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument Profile results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument Profile results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
GitHub
Authenticated Buffer Overflow in the Profile Parameter of /goform/formRemoteControl in UTT HiPER 1250GW Β· Issue #1 Β· jinxjinxboom/cve
Information Vendor of the products: UTT Vendor's website: UTTθΎζ³°-δΈδΈθ·―η±ε¨γδΊ€ζ’ζΊγι²η«ε’εη Affected products: HiPER 1250GW Affected firmware version: <=v3.2.7-210907-180535 Firmware download address: U...
π¨ CVE-2026-5546
A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used.
π@cveNotify
A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used.
π@cveNotify
GitHub
CVE/OLMS at main Β· whatyourname12345/CVE
Contribute to whatyourname12345/CVE development by creating an account on GitHub.
π¨ CVE-2026-5547
A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such manipulation leads to os command injection. It is possible to launch the attack remotely. Multiple endpoints might be affected.
π@cveNotify
A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such manipulation leads to os command injection. It is possible to launch the attack remotely. Multiple endpoints might be affected.
π@cveNotify
GitHub
tenda-ac10v4-vulnerabilities/findings/CRITICAL-03-command-injection-formaddmacfilterrule.md at main Β· somanyerrors/tenda-ac10v4β¦
Contribute to somanyerrors/tenda-ac10v4-vulnerabilities development by creating an account on GitHub.
π¨ CVE-2026-5548
A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.
π@cveNotify
A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.
π@cveNotify
GitHub
tenda-ac10v4-vulnerabilities/findings/CRITICAL-04-stackoverflow-fromsystoolchangepwd.md at main Β· somanyerrors/tenda-ac10v4-vulnerabilities
Contribute to somanyerrors/tenda-ac10v4-vulnerabilities development by creating an account on GitHub.
π¨ CVE-2026-5549
A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
π@cveNotify
A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
π@cveNotify
GitHub
tenda-ac10v4-vulnerabilities/findings/CRITICAL-05-exposed-rsa-private-key.md at main Β· somanyerrors/tenda-ac10v4-vulnerabilities
Contribute to somanyerrors/tenda-ac10v4-vulnerabilities development by creating an account on GitHub.
π¨ CVE-2026-5550
A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.
π@cveNotify
A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.
π@cveNotify
GitHub
tenda-ac10v4-vulnerabilities/findings/HIGH-01-getvalue-229-callers.md at main Β· somanyerrors/tenda-ac10v4-vulnerabilities
Contribute to somanyerrors/tenda-ac10v4-vulnerabilities development by creating an account on GitHub.
π¨ CVE-2026-5551
A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
GitHub
itsourcecode Free Hotel Reservation System V1.0 "/hotel/admin/login.php" SQL injection Β· Issue #1 Β· jasonwong666/cve
itsourcecode Free Hotel Reservation System V1.0 "/hotel/admin/login.php" SQL injection NAME OF AFFECTED PRODUCT(S) Free Hotel Reservation System Vendor Homepage https://itsourcecode.com/f...
π¨ CVE-2026-5552
A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
π@cveNotify
A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
π@cveNotify
GitHub
phpgurukul Online Shopping Portal Project V2.1 /sub-category.php SQL injection Β· Issue #10 Β· f1rstb100d/CVE
phpgurukul Online Shopping Portal Project V2.1 /sub-category.php SQL injection NAME OF AFFECTED PRODUCT(S) Online Shopping Portal Project Vendor Homepage https://phpgurukul.com/shopping-portal-free...
π¨ CVE-2026-5553
A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
π@cveNotify
A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
π@cveNotify
GitHub
itsourcecode Online Cellphone System V1.0 "/cp/available.php" SQL injection Β· Issue #3 Β· Wzl731/test
itsourcecode Online Cellphone System V1.0 "/cp/available.php" SQL injection NAME OF AFFECTED PRODUCT(S) Online Cellphone System Vendor Homepage https://itsourcecode.com/free-projects/php-...
π¨ CVE-2026-5554
A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify