Common Vulnerabilities and Exposures (CVE)

CVE-2026-105707

Oct 6, 2026 05:00:16 UTC

A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is ...

CVE-2026-102779

Oct 6, 2026 04:50:07 UTC

Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, con...

CVE-2026-102777

Oct 6, 2026 04:49:49 UTC

Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the ser...

CVE-2026-105706

Oct 6, 2026 04:45:12 UTC

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been...

CVE-2026-105705

Oct 6, 2026 04:30:16 UTC

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be c...

CVE-2026-105704

Oct 6, 2026 04:15:13 UTC

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be exe...

CVE-2026-105703

Oct 6, 2026 04:00:10 UTC

A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. T...

CVE-2026-45524

Oct 6, 2026 03:56:16 UTC

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

CVE-2026-49880

Oct 6, 2026 03:56:15 UTC

In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVE-2026-49885

Oct 6, 2026 03:56:14 UTC

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVE-2026-55266

Oct 6, 2026 03:56:13 UTC

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVE-2026-49937

Oct 6, 2026 03:56:13 UTC

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...

CVE-2026-55286

Oct 6, 2026 03:56:12 UTC

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVE-2026-58859

Oct 6, 2026 03:56:11 UTC

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-28625

Oct 6, 2026 03:56:10 UTC

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.