🔓 VULNERABILITIES & CVEs
-
CVE-2026-16226 in SourceCodester Pizzafy Ecommerce System — CVSS 4.7 — ThreatIntel CVE-2026-16226 affects the admin_class_novo.php save_settings function in SourceCodester Pizzafy Ecommerce System, presenting a moderate security risk.
- detail: Moderate severity vulnerability requiring patch or mitigation.
-
CVE-2026-16227 in SourceCodester Class and Exam Timetabling System — ThreatIntel SQL injection vulnerability in edit_subject.php could allow unauthorized data access or modification.
- detail: Requires urgent review and patching.
-
CVE-2026-16228 in SourceCodester Class and Exam Timetabling System — ThreatIntel SQL injection vulnerability in edit_schoolyr.php exposes the system to injection attacks.
- detail: Patch recommended to prevent exploitation.
-
CVE-2026-16229 in itsourcecode Courier Management System — ThreatIntel Cross-site scripting flaw in index.php could enable injection of malicious scripts.
- detail: Input validation improvements needed.
-
Linux Kernel Vulnerabilities CVE-2026-53367 to CVE-2026-53372 — ThreatIntel Multiple vulnerabilities in Linux kernel components including iommu/vt-d, RDMA/ionic, perf/x86/intel, udf, f2fs, and selinux have been identified.
- detail: Issues range from improper flag usage to auditing flaws.
- detail: Users should update kernels to latest versions to mitigate risks.
-
CVE-2026-16225 in davenardella snap7 s7_peer.cpp — ThreatIntel Out-of-bounds write vulnerability in NegotiatePDULength function could lead to memory corruption.
- detail: Security patch required.
-
CVE-2026-16224 in jxxghp MoviePilot Application API — ThreatIntel Improper authorization vulnerability could allow unauthorized API access.
- detail: Access controls need strengthening.