CVE-2026-9484
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getCla
CVSS
6.3
Medio
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 25 may 2026 · Última mod.: 23 jul 2026 · CWE-266 · CWE-285
0.3%EPSS · 30 días0.3%
2026-08-062026-09-02
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
- github.comhttps://github.com/Jack-MRJ/Student-Grades-Management-System-Vulnerability-Report
- vuldb.comhttps://vuldb.com/submit/814038
- vuldb.comhttps://vuldb.com/submit/814039
- vuldb.comhttps://vuldb.com/submit/814042
- vuldb.comhttps://vuldb.com/vuln/365465
- vuldb.comhttps://vuldb.com/vuln/365465/cti
- www.sourcecodester.comhttps://www.sourcecodester.com/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-79989——
——0The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).1dCVE-2026-848075.4 MED—
——0Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches an existing team; because the endpoints POST /api/customers/{id}/team, POST /api/projects/{id}/team, and POST /api/activities/{id}/team reuse an existing team of the same name and add the current user as teamlead without verifying that the user is authorized to manage that team, the attacker gains unauthorized team-lead (administration) rights over the existing team. Fixed in 2.65.0.1dCVE-2026-847994.3 MED—
——0Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators.1dCVE-2026-817698.8 ALT—
——0Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.
This issue affects Booking Hub: from n/a through 1.3.1.1dCVE-2026-812949.8 CRÍ—
——0Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.1dCVE-2026-841158.3 ALT20.5%
——6A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. It is recommended to upgrade the affected component.2d