A vulnerability was found in itsourcecode School Management System 1.0. It has been declared as critical. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection.
This vulnerability is identified as CVE-2026-86268. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability was found in itsourcecode Information System Society Membership System 1.0. It has been classified as critical. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection.
This vulnerability is referenced as CVE-2026-86267. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability labeled as problematic has been found in Red Hat Enterprise Linux. Affected by this issue is some unknown functionality of the component XWD Image Handler. The manipulation of the argument bytes-per-line results in out-of-bounds read.
This vulnerability is identified as CVE-2026-80101. The attack is only possible with local access. There is not any exploit available.
A vulnerability has been found in Drupal Disable Login Page Plugin and classified as critical. This affects an unknown part. This manipulation causes improper restriction of excessive authentication attempts.
The identification of this vulnerability is CVE-2026-18260. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.45/7.1.9. The affected element is the function perf_event_open of the component perf. The manipulation leads to time-of-check time-of-use.
This vulnerability is traded as CVE-2026-74753. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in songxpu stomper. It has been rated as problematic. This affects the function epoll_wait of the component STOMP. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-26445. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in VMware Spring Integration up to 5.5.21/6.4.12/6.5.10/7.0.5/7.1.0. Affected is the function readObject of the component SerializingHttpMessageConverter. Executing a manipulation can lead to deserialization.
This vulnerability is handled as CVE-2026-47864. The attack can be executed remotely. There is not any exploit available.
A vulnerability has been found in VMware Spring Batch up to 5.2.6/6.0.4 and classified as critical. Affected by this vulnerability is the function JobParameterDeserializer of the component Job Parameter Deserialization. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2026-47875. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Spring Framework up to 7.0.8. It has been classified as problematic. This affects an unknown part of the component Aalto XML Processor. This manipulation causes allocation of resources.
The identification of this vulnerability is CVE-2026-47891. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability described as problematic has been identified in Spring Security up to 7.1.0. Affected by this issue is some unknown functionality of the component Consent Page. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2026-47877. It is possible to launch the attack remotely. No exploit is available.
A vulnerability labeled as problematic has been found in jahlives openssl_encrypt up to 1.4.8. This issue affects some unknown processing. Such manipulation leads to improper authentication.
This vulnerability is traded as CVE-2026-81680. An attack has to be approached locally. There is no exploit available.
The affected component should be upgraded.
A vulnerability categorized as problematic has been discovered in jahlives openssl-encrypt up to 1.4.8. This affects an unknown function of the component Settings Screen. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2026-81683. The attack needs to be launched locally. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability categorized as critical has been discovered in VMware Spring Framework up to 7.0.8/6.2.19. This affects an unknown function of the component Server-Sent Events. The manipulation results in crlf injection.
This vulnerability is identified as CVE-2026-47890. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in wger-project wger up to 2.5 and classified as problematic. This vulnerability affects unknown code of the component TSV Export. Executing a manipulation of the argument first_name/last_name can lead to injection.
The identification of this vulnerability is CVE-2026-86257. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in wger-project Wger up to 2.5.0 and classified as problematic. This affects the function trainer_login of the file wger/core/views/user.py of the component Impersonation. Performing a manipulation of the argument Next results in open redirect.
This vulnerability was named CVE-2026-86256. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.