A vulnerability, which was classified as problematic, has been found in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program.
This vulnerability is cataloged as CVE-2026-15540. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload.
This vulnerability is listed as CVE-2026-15539. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability classified as critical has been found in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is tracked as CVE-2026-15538. The attack is possible to be carried out remotely. No exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability described as critical has been identified in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection.
This vulnerability is identified as CVE-2026-15537. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability marked as critical has been reported in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid leads to sql injection.
This vulnerability is referenced as CVE-2026-15536. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability labeled as critical has been found in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument index_meta.faiss can lead to deserialization.
The identification of this vulnerability is CVE-2026-15535. The attack may be launched remotely. Furthermore, there is an exploit available.
This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability identified as problematic has been detected in zephyrproject zephyr up to 4.4.x. Affected by this vulnerability is the function usbh_device_disconnect of the file subsys/usb/host/usbh_device.c of the component USB Host Stack. Performing a manipulation of the argument root results in use after free.
This vulnerability was named CVE-2026-10663. The attack needs to be approached locally. There is no available exploit.
A vulnerability categorized as problematic has been discovered in zephyrproject Zephyr up to 4.4.x. Affected is the function numaker_hsusbd_ep_trigger of the file drivers/usb/udc/udc_numaker.c of the component Nuvoton NuMaker HSUSBD USB Device-Controller Driver. Such manipulation of the argument CEPTXCNT leads to denial of service.
This vulnerability is uniquely identified as CVE-2026-10668. Local access is required to approach this attack. No exploit exists.
A vulnerability was found in zephyrproject zephyr up to 4.4.x. It has been rated as very critical. This impacts the function parse_ipv4 of the file subsys/net/ip/utils.c of the component IPv4 Parser. This manipulation of the argument port causes stack-based buffer overflow.
This vulnerability is handled as CVE-2026-10666. The attack can be initiated remotely. There is not any exploit available.