Aggregator
Submit #850366: code-projects.org Hotel and Tourism Reservation In PHP 1.0 SQL Injection [Accepted]
3 weeks 2 days ago
Submit #850366 / VDB-376345
anubhav106
Submit #850365: code-projects.org Hotel and Tourism Reservation In PHP 1.0 SQL Injection [Accepted]
3 weeks 2 days ago
Submit #850365 / VDB-376344
anubhav106
Submit #850344: code-projects.org Hotel and Tourism Reservation In PHP 1.0 SQL Injection [Accepted]
3 weeks 2 days ago
Submit #850344 / VDB-376343
anubhav106
CVE-2026-14753 | mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be Note Handler/Assignment /PHP/objects/notes assignment_item_id authorization (EUVD-2026-41759)
3 weeks 2 days ago
A vulnerability was found in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. It has been rated as critical. This impacts an unknown function of the file /PHP/objects/notes of the component Note Handler/Assignment Handler. Performing a manipulation of the argument assignment_item_id results in authorization bypass.
This vulnerability is identified as CVE-2026-14753. The attack can be initiated remotely. Additionally, an exploit exists.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
CVE-2026-14752 | mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be add_into_dictionary.php add_definition reference cross site scripting (EUVD-2026-41758)
3 weeks 2 days ago
A vulnerability was found in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. It has been declared as problematic. This affects the function add_definition of the file application/PHP/objects/notes/add_into_dictionary.php. Such manipulation of the argument reference leads to cross site scripting.
This vulnerability is referenced as CVE-2026-14752. It is possible to launch the attack remotely. Furthermore, an exploit is available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
CVE-2026-14751 | mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be search_scratch_data.php search_scratch_data field_name sql injection (EUVD-2026-41757)
3 weeks 2 days ago
A vulnerability was found in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. It has been classified as critical. The impacted element is the function Notes_controller::search_scratch_data of the file application/PHP/objects/notes/search_scratch_data.php. This manipulation of the argument field_name causes sql injection.
The identification of this vulnerability is CVE-2026-14751. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
CVE-2026-14750 | mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be accessing_dictionary_authorization.php accessing_dictionary_authorization Password sql injection (EUVD-2026-41756)
3 weeks 2 days ago
A vulnerability was found in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be and classified as critical. The affected element is the function Notes_controller::accessing_dictionary_authorization of the file application/PHP/objects/notes/accessing_dictionary_authorization.php. The manipulation of the argument Password results in sql injection.
This vulnerability was named CVE-2026-14750. The attack may be performed from remote. In addition, an exploit is available.
This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
Submit #850343: code-projects.org Hotel and Tourism Reservation In PHP 1.0 SQL Injection [Duplicate]
3 weeks 2 days ago
Submit #850343 / VDB-367583
anubhav106
Submit #849496: mjperpinosa stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be Authorization Bypass Through User-Controlled SQL Primary Key [Accepted]
3 weeks 2 days ago
Submit #849496 / VDB-376342
gscsd
Submit #849495: mjperpinosa stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be Cross Site Scripting [Accepted]
3 weeks 2 days ago
Submit #849495 / VDB-376341
cnluminous
Submit #849494: mjperpinosa stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be SQL Injection [Accepted]
3 weeks 2 days ago
Submit #849494 / VDB-376340
cnluminous
Submit #849483: mjperpinosa stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be SQL Injection [Accepted]
3 weeks 2 days ago
Submit #849483 / VDB-376339
gscsd
CVE-2026-14749 | mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be calculate.php eval mathematical_sentence code injection (EUVD-2026-41755)
3 weeks 2 days ago
A vulnerability has been found in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be and classified as critical. Impacted is the function eval of the file application/pages/imba_calculator/calculate.php. The manipulation of the argument mathematical_sentence leads to code injection.
This vulnerability is uniquely identified as CVE-2026-14749. The attack is possible to be carried out remotely. Moreover, an exploit is present.
This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
1000 циклов и потеря лишь 0,034% за цикл. Графен помог спасти многообещающие серные батареи от быстрой смерти
3 weeks 2 days ago
Разработка Университета Тохоку показала, как превратить капризную лабораторную технологию в более жизнеспособную платформу.
Submit #849414: mjperpinosa stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be Code Injection [Accepted]
3 weeks 2 days ago
Submit #849414 / VDB-376338
gscsd
仙女座发现新卫星星系
3 weeks 2 days ago
天文学家在距离地球约 250 万光年的仙女座星系附近,发现了一个新的超暗矮星系,命名为仙女座 XXXVI(Andromeda XXXVI,其中 XXXVI 为罗马数字 36),代表它是目前正式命名的第 36 个仙女座卫星星系。研究显示,它可能是迄今在仙女座星系周围发现最暗淡的卫星星系之一。这个星系年龄约达 125 亿年。仙女座星系是距离银河系最近的巨大螺旋星系,周围环绕着许多受到重力束缚的矮卫星星系,因此被视为研究星系形成的天然实验室。目前理论预测,仙女座可能拥有多达约 90 个卫星星系,但迄今仅发现约 40 个,其中只有约 15 个属于超暗矮星系。仙女座 XXXVI 的发现显示,在仙女座周围可能仍隐藏着大量尚未被发现的极暗小星系。
Claude открыл дорогу к бесплатным VIP-билетам на главные фестивали США
3 weeks 2 days ago
Хакер через SQL-инъекцию получил доступ к базе Front Gate Tickets с сотнями таблиц.
CVE-2025-13475 | WSO2 Identity Server/API Manager prior 5.10.0/5.10.0.382 authentication bypass (EUVD-2025-210427)
3 weeks 2 days ago
A vulnerability, which was classified as critical, was found in WSO2 Identity Server and API Manager. This issue affects some unknown processing. Executing a manipulation can lead to authentication bypass using alternate channel.
This vulnerability is handled as CVE-2025-13475. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-14535 | trailofbits fickling up to 0.1.11 shorten_code protection mechanism (GHSA-cffv-grgg-g429 / EUVD-2026-41676)
3 weeks 2 days ago
A vulnerability, which was classified as critical, has been found in trailofbits fickling up to 0.1.11. This vulnerability affects the function shorten_code. Performing a manipulation results in protection mechanism failure.
This vulnerability is known as CVE-2026-14535. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com