A vulnerability, which was classified as critical, was found in WSO2 Identity Server and API Manager. This issue affects some unknown processing. Executing a manipulation can lead to authentication bypass using alternate channel.
This vulnerability is handled as CVE-2025-13475. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in trailofbits fickling up to 0.1.11. This vulnerability affects the function shorten_code. Performing a manipulation results in protection mechanism failure.
This vulnerability is known as CVE-2026-14535. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in trailofbits fickling up to 0.1.10. This affects the function fickling.load of the file fickle.py. Such manipulation leads to incomplete blacklist.
This vulnerability is traded as CVE-2026-14534. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]
A vulnerability classified as critical has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown functionality of the file mcp-wiki/src/mcp_wiki/server.py of the component mcp-wiki/wiki-summary. This manipulation of the argument url causes server-side request forgery.
This vulnerability appears as CVE-2026-14748. The attack may be initiated remotely. In addition, an exploit is available.
This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability described as critical has been identified in code-projects Real State Services 1.0. Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. The manipulation of the argument amen results in sql injection.
This vulnerability is reported as CVE-2026-14747. The attack can be launched remotely. No exploit exists.
A vulnerability marked as critical has been reported in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection.
This vulnerability is documented as CVE-2026-14746. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability labeled as critical has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /single-list_rent.php. Executing a manipulation of the argument ID can lead to sql injection.
This vulnerability is registered as CVE-2026-14745. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability identified as critical has been detected in code-projects Real State Services 1.0. This affects an unknown function of the file /normalHomeRent.php. Performing a manipulation of the argument loc results in sql injection.
This vulnerability is cataloged as CVE-2026-14744. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability categorized as critical has been discovered in code-projects Real State Services 1.0. The impacted element is an unknown function of the file /normalHomeSale.php. Such manipulation of the argument loc leads to sql injection.
This vulnerability is listed as CVE-2026-14743. The attack may be performed from remote. In addition, an exploit is available.