Common Vulnerabilities and Exposures (CVE)

CVE-2026-78115

Aug 23, 2026 09:45:10 UTC

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of the argument id/user...

CVE-2026-10053

Aug 23, 2026 09:27:01 UTC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code executio...

CVE-2026-78155

Aug 23, 2026 09:26:46 UTC

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

CVE-2026-78112

Aug 23, 2026 09:15:09 UTC

A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes sql injection. The attack may be initiate...

CVE-2026-77116

Aug 23, 2026 06:00:18 UTC

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing...

CVE-2026-77115

Aug 23, 2026 06:00:18 UTC

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.

CVE-2026-77003

Aug 23, 2026 06:00:18 UTC

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publ...

CVE-2026-14853

Aug 23, 2026 06:00:17 UTC

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to creat...

CVE-2026-13598

Aug 23, 2026 06:00:17 UTC

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leadi...

CVE-2026-14764

Aug 23, 2026 05:43:14 UTC

A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to...

CVE-2026-78063

Aug 23, 2026 04:30:10 UTC

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be ...

CVE-2026-78062

Aug 23, 2026 04:15:10 UTC

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to ...

CVE-2026-78061

Aug 23, 2026 03:45:09 UTC

A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to se...

CVE-2026-78060

Aug 23, 2026 03:30:07 UTC

A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cr...

CVE-2026-78059

Aug 23, 2026 03:15:09 UTC

A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scr...