A vulnerability, which was classified as problematic, was found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization.
This vulnerability is documented as CVE-2026-10294. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability, which was classified as critical, has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formFireWall. This manipulation of the argument Profile causes stack-based buffer overflow.
This vulnerability is registered as CVE-2026-10293. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability classified as critical was found in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2026-10292. The attack may be launched remotely. Furthermore, there is an exploit available.
CVE-2026-0257 lets attackers forge Palo Alto GlobalProtect auth cookies and bypass VPN login. Exploitation confirmed since May 17. Palo Alto Networks addressed the vulnerability CVE-2026-0257 on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer environments. The flaw impacts the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS […]
A vulnerability classified as problematic has been found in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the component Session Grep Endpoint. The manipulation of the argument body.pattern leads to inefficient regular expression complexity.
This vulnerability is listed as CVE-2026-10291. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection.
This vulnerability is tracked as CVE-2026-10290. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability marked as problematic has been reported in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting.
This vulnerability is identified as CVE-2026-10289. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability labeled as critical has been found in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication.
This vulnerability is referenced as CVE-2026-10288. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability identified as critical has been detected in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery.
The identification of this vulnerability is CVE-2026-10287. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.