CVE-2026-105179
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user
CVSS
2.7
Bajo
EPSS
0.2%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 5 oct 2026 · Última mod.: 6 oct 2026 · CWE-310 · CWE-311
Sin historial EPSS suficiente todavía.
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user.php of the component Password Handler. Executing a manipulation of the argument Password can lead to missing encryption of sensitive data. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-788607.8 ALT—
——0An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext7hCVE-2026-1052453.7 BAJ9.4%
——3A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.2dCVE-2026-965503.7 BAJ10.6%
——3A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_pro/src/main/java/cn/sfturing/utils/MailUtil.java. Performing a manipulation results in cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is assessed as difficult. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.8dCVE-2026-965493.3 BAJ0.2%
——0A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_pro/src/main/java/cn/sfturing/service/impl/CommonUserServiceImpl.java. Such manipulation leads to cleartext storage of sensitive information. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.13dCVE-2026-927575.5 MED0.0%
——0Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.12dCVE-2026-927565.5 MED0.0%
——0Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.12d