Search Results (91074 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-105920 1 Kusalkasilva 1 Learning-management-system 2026-10-06 7.3 High
A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The impacted element is an unknown function of the file student_signup.php of the component Student Registration Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-25272 2026-10-06 6.7 Medium
Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.
CVE-2026-25263 2026-10-06 6.6 Medium
Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters.
CVE-2026-105807 1 Sourcecodester 1 Simple Student Information System 2026-10-06 7.3 High
A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely.
CVE-2026-105776 1 Bhagya3929 1 Employee-movement-tracking-and-monitoring-website-for-iocl 2026-10-06 7.3 High
A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-105708 1 Imgproxy 1 Imgproxy 2026-10-06 4.3 Medium
A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-105487 1 Yogeshojha 1 Rengine 2026-10-06 6.3 Medium
A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
CVE-2026-12380 2026-10-06 6.1 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. E-Commerce Pack allows Reflected XSS. This issue affects E-Commerce Pack: through 2026-10-06. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-98244 1 Linux 1 Linux Kernel 2026-10-06 N/A
In the Linux kernel, the following vulnerability has been resolved: btrfs: clear free space tree creation state on rebuild failure btrfs_rebuild_free_space_tree() sets BTRFS_FS_CREATING_FREE_SPACE_TREE before rebuilding the free space tree. Several error paths return without clearing this flag. The transaction restart failure path can leave the flag set on a live filesystem, causing delayed reference processing to be skipped. Clear it on all free space tree rebuild failure paths. Keep BTRFS_FS_FREE_SPACE_TREE_UNTRUSTED set, since a failed rebuild leaves the free space tree untrusted. Callers must fall back to extent-tree caching.
CVE-2026-84854 1 Wibu-systems-ag 1 Wibukey 2026-10-06 7 High
In the WibuKey driver for Windows below Version 6.72, insufficient validation of user input when calculating the size of a kernel buffer could cause small amounts of data to be written outside the intended kernel buffer. This can lead to a system crash. Under unfavorable circumstances, adjacent kernel memory may be modified.
CVE-2026-105809 1 Sourcecodester 1 Simple Student Information System 2026-10-06 4.3 Medium
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
CVE-2026-105918 1 Kusalkasilva 1 Learning-management-system 2026-10-06 7.3 High
A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-97300 2026-10-06 6.5 Medium
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
CVE-2026-39760 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
CVE-2026-39750 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions.
CVE-2026-39748 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions.
CVE-2026-39745 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Contact Form to DB by BestWebSoft <= 1.7.6 versions.
CVE-2026-39731 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Database for CF7 <= 1.2.6 versions.
CVE-2026-39727 2026-10-06 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions.
CVE-2026-39726 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions.