A vulnerability was found in projectworlds Car Rental System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /message_admin.php of the component Parameter Handler. Such manipulation of the argument Message leads to sql injection.
This vulnerability is traded as CVE-2026-5637. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. It has been classified as critical. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection.
This vulnerability appears as CVE-2026-5636. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection.
This vulnerability is reported as CVE-2026-5635. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability has been found in projectworlds Car Rental Project 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /book_car.php of the component Parameter Handler. The manipulation of the argument fname leads to sql injection.
This vulnerability is documented as CVE-2026-5634. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability, which was classified as critical, was found in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-5633. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability, which was classified as critical, has been found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication.
This vulnerability is cataloged as CVE-2026-5632. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability classified as critical was found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/server_utils.py of the component ws Endpoint. Such manipulation of the argument args leads to code injection.
This vulnerability is listed as CVE-2026-5631. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability classified as problematic has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2026-5630. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability described as critical has been identified in Belkin F9K1015 1.00.10. The affected element is the function formSetFirewall of the file /goform/formSetFirewall. The manipulation of the argument webpage results in stack-based buffer overflow.
This vulnerability is identified as CVE-2026-5629. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.