A vulnerability, which was classified as problematic, has been found in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Performing a manipulation results in out-of-bounds read. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is cataloged as CVE-2026-13522. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such manipulation of the argument course_year_section leads to sql injection.
This vulnerability is listed as CVE-2026-13521. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability classified as critical has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql injection.
This vulnerability is tracked as CVE-2026-13520. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability classified as problematic has been found in open-webui Open WebUI. Affected by this vulnerability is an unknown functionality of the file /api/chat/completions. The manipulation of the argument image_url leads to information disclosure.
This vulnerability is documented as CVE-2026-54009. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in open-webui Open WebUI. This vulnerability affects unknown code of the component Prompt History. Such manipulation leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2026-54015. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in n8n-io n8n up to 1.123.42/2.20.6/2.21.0. This impacts an unknown function of the component Source Control Feature. This manipulation causes sql injection.
This vulnerability is handled as CVE-2026-44792. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in open-webui Open WebUI up to 0.8.10. Affected by this issue is some unknown functionality of the component IO Handler. Performing a manipulation results in incorrectly-resolved name.
This vulnerability is known as CVE-2026-54022. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in n8n-io n8n up to 1.123.42/2.20.6/2.21.0. Affected by this issue is some unknown functionality. Such manipulation leads to argument injection.
This vulnerability is documented as CVE-2026-44790. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability classified as critical has been found in n8n-io n8n up to 1.123.42/2.20.6/2.21.0. The impacted element is an unknown function of the component HTTP Request Handler. This manipulation causes improperly controlled modification of object prototype attributes.
This vulnerability appears as CVE-2026-44789. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in n8n-io n8n up to 1.123.42/2.20.6/2.21.0. This impacts an unknown function. Performing a manipulation results in improperly controlled modification of object prototype attributes.
This vulnerability is known as CVE-2026-44791. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability marked as problematic has been reported in open-webui Open WebUI up to 0.9.5. Affected is an unknown function of the component JavaScript Execution. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-54011. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.