Aggregator
[Virtual Event] Building a Secure AI Strategy for the Enterprise
1 month hence
CVE-2026-86228 | JeecgBoot up to 3.9.3 AiragModelController.java exportXls credential access control (Issue 9600)
1 hour 1 minute ago
A vulnerability, which was classified as problematic, was found in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls.
This vulnerability is referenced as CVE-2026-86228. It is possible to launch the attack remotely. Furthermore, an exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-52924
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
sctp: purge outqueue on stale COOKIE-ECHO handling
sctp_stream_update() is only invoked when the association is moved into
COOKIE_WAIT during association setup/reconfiguration. In this path, the
outbound ...
CVE-2026-73749
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 5 - Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could ...
CVE-2026-20354
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 8 - Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to ...
CVE-2026-43502
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 9 - In the Linux kernel, the following vulnerability has been resolved:
net/rds: handle zerocopy send cleanup before the message is queued
A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.
The purge path currently ...
CVE-2026-85046
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 9 - Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-20355
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 8 - Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to ...
CVE-2026-20279
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 2 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered ...
CVE-2026-20274
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 2 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered ...
CVE-2026-32475
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 6 - Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.
This issue affects Elementor Pro: from n/a through 4.2.1.
CVE-2025-36911
1 hour 2 minutes ago
Currently trending CVE - Hype Score: 5 - In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for ...
CVE-2026-86227 | valkey-io valkey up to 9.0.5/9.1.1 src/kvstore.c kvstoreGetHashtable didx out-of-bounds (Issue 4222)
1 hour 6 minutes ago
A vulnerability, which was classified as problematic, has been found in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-86227. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
To fix this issue, it is recommended to deploy a patch.
Exploitation requires cluster mode plus attacker-controlled dump.rdb at startup (data-dir write access, replication feed, or a stored crafted RDB) - an attacker-position DoS at boot, not network pre-auth. The issue report was closed stating it "is worth fixing for the sake of memory safety… but I don't think it meets our bar for a security disclosure."
vuldb.com
CVE-2026-86226 | Projectwolds Online Attendance System 1.0 profile.php email cross site scripting
1 hour 9 minutes ago
A vulnerability classified as problematic was found in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting.
This vulnerability was named CVE-2026-86226. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2026-86225 | SourceCodester Class and Exam Timetabling System 1.0 modal_add_room.php mysqli_query room_name sql injection
1 hour 16 minutes ago
A vulnerability classified as critical has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-86225. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2026-86224 | SourceCodester Class and Exam Timetabling System 1.0 modal_add_product.php mysqli_query fname sql injection
1 hour 16 minutes ago
A vulnerability described as critical has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection.
This vulnerability is handled as CVE-2026-86224. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2026-86223 | SourceCodester Class and Exam Timetabling System 1.0 modal_add_coursea.php mysqli_query course sql injection
1 hour 16 minutes ago
A vulnerability marked as critical has been reported in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection.
This vulnerability is known as CVE-2026-86223. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2026-86222 | SourceCodester Class and Exam Timetabling System 1.0 modal_add_course2.php mysqli_query course sql injection
1 hour 16 minutes ago
A vulnerability labeled as critical has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection.
This vulnerability is traded as CVE-2026-86222. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2026-86221 | SourceCodester Class and Exam Timetabling System 1.0 modal_add_course1.php mysqli_query course sql injection
1 hour 16 minutes ago
A vulnerability identified as critical has been detected in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection.
This vulnerability appears as CVE-2026-86221. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com