A vulnerability labeled as problematic has been found in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-3408. The attack can be launched remotely. Moreover, an exploit is present.
It is best practice to apply a patch to resolve this issue.
A vulnerability identified as problematic has been detected in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow.
This vulnerability is handled as CVE-2026-3407. It is possible to launch the attack on the local host. Additionally, an exploit exists.
Applying a patch is the recommended action to fix this issue.
It appears that the issue is not reproducible all the time.
A vulnerability categorized as critical has been discovered in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection.
This vulnerability is known as CVE-2026-3406. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in thinkgem JeeSite up to 5.15.1. It has been rated as problematic. The affected element is an unknown function of the component Connection Handler. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-3405. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in thinkgem JeeSite up to 5.15.1. It has been declared as problematic. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference.
This vulnerability appears as CVE-2026-3404. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in PHPGurukul Student Record Management System 1.0. It has been classified as problematic. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting.
This vulnerability is reported as CVE-2026-3403. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability was found in PHPGurukul Student Record Management System up to 1.0 and classified as problematic. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting.
This vulnerability is documented as CVE-2026-3402. The attack can be executed remotely. Additionally, an exploit exists.