A vulnerability classified as problematic has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2026-5630. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability classified as critical was found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/server_utils.py of the component ws Endpoint. Such manipulation of the argument args leads to code injection.
This vulnerability is listed as CVE-2026-5631. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection.
This vulnerability is reported as CVE-2026-5635. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. It has been classified as critical. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection.
This vulnerability appears as CVE-2026-5636. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability described as problematic has been identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admin/Add%20notice/notice.php of the component Admin Add Endpoint. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting.
This vulnerability is referenced as CVE-2026-5643. It is possible to launch the attack remotely. Furthermore, an exploit is available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability classified as problematic has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /admin/Add%20notice/batch-notice.php. Performing a manipulation of the argument $_SERVER['PHP_SELF'] results in cross site scripting.
This vulnerability is identified as CVE-2026-5644. The attack can be initiated remotely. Additionally, an exploit exists.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability classified as critical was found in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.php of the component Parameter Handler. Executing a manipulation of the argument mpesa can lead to sql injection.
This vulnerability is tracked as CVE-2026-5645. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability, which was classified as critical, has been found in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is listed as CVE-2026-5646. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as problematic, was found in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/admin_feature.php of the component Add Product Page. The manipulation of the argument product_name results in cross site scripting.
This vulnerability is cataloged as CVE-2026-5647. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in code-projects Simple Laundry System 1.0 and classified as critical. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection.
This vulnerability is registered as CVE-2026-5648. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability was found in code-projects Online Application System for Admission 1.0 and classified as critical. This issue affects some unknown processing of the file /enrollment/admsnform.php of the component Endpoint. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-5649. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability was found in Linux Kernel up to 6.1.93/6.6.33/6.9.4. It has been declared as critical. This vulnerability affects the function btrfs_set_item_key_safe of the file fs/btrfs/ctree.c. The manipulation results in denial of service.
This vulnerability is identified as CVE-2024-37354. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.10.217. It has been rated as critical. Affected by this issue is the function USERGS_SYSRET64 of the component Xen. The manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2021-4440. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.94/6.6.34/6.9.4. The affected element is the function __folio_start_writeback of the file folio/page of the component nilfs2. Executing a manipulation can lead to memory corruption.
This vulnerability appears as CVE-2024-37078. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.9.4. It has been classified as critical. This affects the function platform_data of the component lgdt3306a. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2022-48772. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.10.9. Affected by this vulnerability is the function get_stashed_dentry of the component libfs. This manipulation causes null pointer dereference.
This vulnerability is handled as CVE-2024-46801. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.10.9. Affected by this issue is the function am65_cpsw_ndo_xdp_xmit of the file /xdp-trafficgen of the component Virtual Address Handler. Performing a manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2024-46799. The attack can only be performed from the local network. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.10.9. Affected is the function snd_pcm_suspend_all. The manipulation results in use after free.
This vulnerability is known as CVE-2024-46798. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.