A vulnerability, which was classified as critical, was found in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection.
This vulnerability is traded as CVE-2026-10265. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal.
This vulnerability appears as CVE-2026-10264. The attacker needs to be present on the local network. In addition, an exploit is available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection.
This vulnerability is reported as CVE-2026-10263. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability classified as critical has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection.
This vulnerability is documented as CVE-2026-10262. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability described as critical has been identified in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection.
This vulnerability is registered as CVE-2026-10261. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability marked as critical has been reported in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection.
This vulnerability is cataloged as CVE-2026-10260. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability marked as critical has been reported in Microsoft Windows. This affects an unknown part of the component Remote Desktop Licensing Service. This manipulation causes missing authentication.
This vulnerability appears as CVE-2026-26159. The attack requires local access. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability described as critical has been identified in Microsoft Windows. This vulnerability affects unknown code of the component Remote Desktop Licensing Service. Such manipulation leads to missing authentication.
This vulnerability is traded as CVE-2026-26160. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Microsoft Windows. It has been declared as critical. This affects an unknown function of the component Cryptographic Services. Such manipulation leads to insecure storage of sensitive information.
This vulnerability is listed as CVE-2026-26152. The attack must be carried out locally. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability identified as problematic has been detected in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Local Security Authority Subsystem Service. The manipulation leads to buffer over-read.
This vulnerability is documented as CVE-2026-26155. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Microsoft Windows. Affected by this issue is some unknown functionality of the component Hyper-V. The manipulation results in heap-based buffer overflow.
This vulnerability is reported as CVE-2026-26156. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in djangoproject Django up to 4.2.28/5.2.11/6.0.2. It has been rated as problematic. Impacted is an unknown function of the component File-System Backend. The manipulation leads to race condition.
This vulnerability is documented as CVE-2026-25674. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.