A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload.
This vulnerability is registered as CVE-2026-90519. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability, which was classified as critical, was found in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls.
This vulnerability is cataloged as CVE-2026-90518. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass.
This vulnerability is listed as CVE-2026-90517. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability classified as critical was found in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection.
This vulnerability is tracked as CVE-2026-90515. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability classified as critical has been found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection.
This vulnerability is identified as CVE-2026-90516. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability described as critical has been identified in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection.
This vulnerability is referenced as CVE-2026-90514. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability marked as critical has been reported in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing authentication.
The identification of this vulnerability is CVE-2026-90513. It is possible to initiate the attack remotely. There is no exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The project was informed of the problem early through an issue report but has not responded yet.
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.
On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the
A vulnerability labeled as critical has been found in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection.
This vulnerability was named CVE-2026-90511. The attack may be performed from remote. In addition, an exploit is available.
This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
A vulnerability identified as critical has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is uniquely identified as CVE-2026-90510. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.