Skip to content
Threat Feed

July 2026 (30)

high advisory

CVE-2026-12250: Pardus Domain Joiner Vulnerability Exposes Sensitive Information

A high-severity vulnerability, CVE-2026-12250, in TUBITAK BILGEM Software Technologies Research Institute's Pardus Domain Joiner (versions 0.5.2 before 0.5.4) allows local attackers to excavate sensitive information by observing process invocations that expose credentials or other confidential data.

Pardus Domain Joiner 0.5.2 +1 vulnerability linux data-exposure pardus
1c
high advisory

CVE-2026-14754: SQL Injection in code-projects Hotel and Tourism Reservation

A critical SQL injection vulnerability (CVE-2026-14754) in code-projects Hotel and Tourism Reservation 1.0's `/admin/add_room.php` file allows a remote, unauthenticated attacker to manipulate arguments such as `delete_image`, `edit`, `description`, `number`, `price`, `rooms`, or `type` to execute arbitrary SQL commands, leading to sensitive data exposure and potential database compromise.

Hotel and Tourism Reservation 1.0 sql-injection web-application cve code-projects remote-code-execution
1r 1t 1c
high advisory

CVE-2026-14753: mjperpinosa stumasy Authorization Bypass

A critical authorization bypass vulnerability (CVE-2026-14753) has been identified in mjperpinosa stumasy, affecting versions up to and including commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This flaw, residing in an unknown function within the /PHP/objects/notes file of the Note Handler/Assignment Handler component, allows a remote attacker to bypass authorization by manipulating the 'assignment_item_id' argument. A public exploit is available, posing an immediate threat.

stumasy authorization-bypass web-application vulnerability cve
2t 1c 1i
high advisory

CVE-2026-14750 — SQL Injection in mjperpinosa stumasy via Password Argument

A high-severity remote SQL injection vulnerability (CVE-2026-14750) exists in mjperpinosa stumasy up to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be, allowing unauthenticated attackers to manipulate the 'Password' argument in the `Notes_controller::accessing_dictionary_authorization` function to execute arbitrary SQL queries, leading to data exfiltration, manipulation, or potential server compromise via a publicly available exploit.

stumasy sql-injection web-application cve unauthenticated remote-code-execution data-exfiltration
1r 3t 1c
high advisory

CVE-2026-14749: mjperpinosa stumasy Code Injection Vulnerability

A code injection vulnerability (CVE-2026-14749) was identified in mjperpinosa stumasy, affecting versions up to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be, which allows remote attackers to execute arbitrary code by manipulating the 'mathematical_sentence' argument in the 'eval' function of 'application/pages/imba_calculator/calculate.php', with a public exploit available and no vendor response.

stumasy web-vulnerability code-injection rce php
1r 2t 1c
high advisory

CVE-2026-14747: SQL Injection in code-projects Real State Services 1.0

A high-severity SQL Injection vulnerability, CVE-2026-14747, exists in the /addprojectsale.php file of code-projects Real State Services 1.0, allowing remote unauthenticated attackers to manipulate the 'amen' argument for arbitrary SQL query execution, leading to data compromise or unauthorized access.

Real State Services 1.0 sql-injection web-exploitation cve php real-state
1r 1t 1c
high threat

CVE-2026-14746: SQL Injection in code-projects Real State Services

A high-severity SQL injection vulnerability (CVE-2026-14746) exists in code-projects Real State Services 1.0, specifically in the `/addprojectrent.php` file, where the `amen` argument can be manipulated to execute arbitrary SQL commands, enabling remote attackers to achieve unauthorized data access or modification, with public exploit disclosure increasing the risk of active exploitation.

exploited Real State Services 1.0 sql-injection web-vulnerability cve webserver public-exploit
1r 1t 1c
high advisory

CVE-2026-14745: SQL Injection in code-projects Real State Services

A critical SQL injection vulnerability (CVE-2026-14745) affecting code-projects Real State Services version 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/single-list_rent.php' file, potentially leading to data exposure, unauthorized modification, or denial of service, with a public exploit available.

Real State Services 1.0 web-vulnerability sql-injection cve real-estate vulnerability
1r 3t 1c
high advisory

CVE-2026-14744: Remote SQL Injection in code-projects Real State Services 1.0

A critical SQL injection vulnerability (CVE-2026-14744) has been found in code-projects Real State Services version 1.0. The flaw resides in an unknown function within the /normalHomeRent.php file, where manipulating the 'loc' argument allows for remote SQL injection, and a public exploit has been released, posing an immediate threat to affected systems.

Real State Services 1.0 web-exploitation sql-injection cve-2026-14744 initial-access data-exfiltration
1r 4t 1c 6i
high advisory

CVE-2026-14743: Remote SQL Injection in code-projects Real State Services 1.0

A high-severity remote SQL injection vulnerability (CVE-2026-14743) in code-projects Real State Services 1.0 allows an unauthenticated attacker to manipulate the 'loc' argument in the `/normalHomeSale.php` file, leading to arbitrary SQL command execution and potential compromise of confidentiality, integrity, and availability of data, with an exploit publicly available.

Real State Services 1.0 sql-injection webserver vulnerability cve
1r 2t 1c
high advisory

CVE-2026-14737: Hanwang e-Face General Management Platform SQL Injection

A remote SQL injection vulnerability (CVE-2026-14737) affects Hanwang e-Face General Management Platform version 6.3.5.4, specifically within the `/sysAuthStr/querySysAuthStr.do` file, triggered by manipulating argument order, allowing remote attackers to potentially gain unauthorized access to or modify database contents with a publicly available exploit.

e-Face General Management Platform 6.3.5.4 sql-injection web-exploitation vulnerability cve hanwang
1r 1t 1c
high advisory

CVE-2026-14736: Ruijie RG-UAC Unrestricted Upload Vulnerability

A critical unrestricted file upload vulnerability, CVE-2026-14736, in Ruijie RG-UAC up to version 1.0-R1.8.2.p5 allows unauthenticated remote attackers to upload arbitrary files via manipulation of the `upload_image` argument in `user_auth_commit.php`, potentially leading to remote code execution.

RG-UAC firmware up to 1.0-R1.8.2.p5 vulnerability rce unrestricted-file-upload webserver cve-2026-14736
3t 1c
high threat

CVE-2026-14735: SQL Injection Vulnerability in code-projects Smart Parking System

A high-severity SQL injection vulnerability, CVE-2026-14735, exists in code-projects Smart Parking System 1.0, allowing remote attackers to manipulate the `street`, `city`, or `status` arguments in `/parkings/parkings.php` to execute arbitrary SQL queries, potentially leading to arbitrary file read and data exfiltration, with public exploit details available.

exploited Smart Parking System 1.0 sql-injection vulnerability web-application php cve
1r 2t 1c 6i
high advisory

CVE-2026-14734: SQL Injection in SourceCodester Class and Exam Timetabling System

A high-severity SQL injection vulnerability (CVE-2026-14734) exists in SourceCodester Class and Exam Timetabling System version 1.0, allowing unauthenticated remote attackers to manipulate the 'ID' argument in `/edit_product.php` to execute arbitrary SQL queries, with a publicly available exploit increasing the risk of unauthorized data access, modification, or exfiltration.

Class and Exam Timetabling System 1.0 sql-injection web-application cve vulnerability initial-access
1r 3t 1c 6i
high threat

CVE-2026-14733: Remote SQL Injection in SourceCodester Class and Exam Timetabling System

A high-severity SQL injection vulnerability, CVE-2026-14733, exists in SourceCodester Class and Exam Timetabling System 1.0, specifically within the '/edit_coursea.php' file, allowing unauthenticated remote attackers to manipulate the 'ID' argument and execute arbitrary SQL commands due to a publicly available exploit.

exploited Class and Exam Timetabling System 1.0 sql-injection web-application cve
1r 2t 1c
high advisory

CVE-2026-14732: SQL Injection in SourceCodester Class and Exam Timetabling System

A critical SQL injection vulnerability (CVE-2026-14732) in SourceCodester Class and Exam Timetabling System 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands via manipulation of the `ID` argument in `/edit_exam.php`, leading to data exfiltration and potential system compromise.

Class and Exam Timetabling System 1.0 sql-injection web-application cve sourcecodester initial-access
1r 1t 1c
high threat

CVE-2026-14721: UTT HiPER 1250GW Remote Code Execution via Buffer Overflow

A critical stack-based buffer overflow vulnerability (CVE-2026-14721) in UTT HiPER 1250GW firmware versions up to 3.2.7-210907-180535 allows remote, unauthenticated attackers to achieve arbitrary code execution by manipulating the 'ssid' argument in the /goform/ConfigWirelessBase_5g web endpoint, with public exploit disclosure indicating active exploitation risk.

exploited HiPER 1250GW buffer-overflow remote-code-execution network-device web-application
2t 1c
high threat

CVE-2026-14722: Remote Code Injection in TidGi-Desktop Git Repository Import Component

A critical remote code injection vulnerability, CVE-2026-14722, has been identified in tiddly-gittly TidGi-Desktop versions up to 0.13.0, allowing unauthenticated attackers to execute arbitrary code by manipulating the Git Repository Import component, with public exploits available and confirmed active exploitation potential.

exploited TidGi-Desktop vulnerability code-injection remote-code-execution desktop-application
2t 1c 6i
high advisory

CVE-2026-14719: SourceCodester Onlne Examination & Learning Management System Privilege Escalation

A critical remote vulnerability (CVE-2026-14719) has been identified in SourceCodester Onlne Examination & Learning Management System version 1.0. The flaw resides in the Registration Endpoint, specifically within the 'register.php' file, where improper privilege management allows for manipulation of the 'role' argument, leading to unauthorized privilege escalation. A public exploit for this vulnerability has been published, increasing the immediate risk of exploitation.

Onlne Examination & Learning Management System 1.0 privilege-escalation web-application cve sourcecodester improper-privilege-management
1r 2t 1c 1i
high advisory

CVE-2026-14713 — SQL Injection in SourceCodester Pizzafy E-Commerce System

A critical SQL injection vulnerability (CVE-2026-14713) exists in SourceCodester Pizzafy E-Commerce System version 1.0, allowing unauthenticated remote attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the `/admin/ajax.php?action=confirm_order` endpoint, potentially leading to data exfiltration or modification, with a public exploit available.

Pizzafy E-Commerce System 1.0 sql-injection web-vulnerability cve sourcecodester e-commerce
1r 1t 1c
high advisory

CVE-2026-14705: SQL Injection in code-projects Online Examination 1.0

A critical remote SQL injection vulnerability (CVE-2026-14705) exists in code-projects Online Examination 1.0, specifically within the `head.php` file, where manipulation of the `uname` or `password` arguments can lead to arbitrary SQL command execution, which has been publicly disclosed and can be exploited by an unauthenticated attacker.

Online Examination 1.0 sql-injection web-application cve initial-access
1r 1t 1c
high advisory

CVE-2026-14700: Code-Projects Internship Management System SQL Injection Vulnerability

A critical unauthenticated SQL injection vulnerability (CVE-2026-14700) in the 'employer/login.php' endpoint of code-projects Internship Management System 1.0 allows remote attackers to manipulate 'email' or 'password' arguments, potentially leading to unauthorized access and data compromise, with public exploit disclosure increasing risk.

Internship Management System 1.0 sql-injection web-application initial-access php unauthenticated
1r 1t 1c
medium advisory

Detecting Potential ICMP Tunneling Activity for Covert C2 and Exfiltration

This brief describes a critical network threat where attackers leverage ICMP tunneling, a technique to embed command and control (C2) or exfiltrated data within large ICMP Echo payloads, enabling covert communication channels that bypass traditional firewall rules, posing a significant risk of data theft and unauthorized system control.

network-security command-and-control data-exfiltration icmp-tunneling elastic-detection-rule
1r 2t
high advisory

CVE-2026-14695: SourceCodester Multi-Vendor Online Grocery Management System SQL Injection

A high-severity SQL injection vulnerability, CVE-2026-14695, exists in SourceCodester Multi-Vendor Online Grocery Management System 1.0, allowing remote attackers to manipulate the 'Name' argument within the `save_client` function of `classes/Users.php` to execute arbitrary SQL commands, with a public exploit available.

Multi-Vendor Online Grocery Management System 1.0 sql-injection web-vulnerability cve sourcecodester data-theft
1t 1c
low advisory

ICMP Timestamp or Information Request from the Internet

This brief identifies inbound ICMP Timestamp (type 13) or Information (type 15) requests originating from external IP addresses and targeting internal RFC1918 destinations, a legacy diagnostic activity commonly associated with host and path fingerprinting during reconnaissance, active scanning, or OS fingerprinting efforts by an unidentified actor, indicating a potential prelude to more severe attacks.

network_traffic integration network discovery reconnaissance icmp elastic
1r 2t
high advisory

CVE-2026-14690: Improper Authorization in SourceCodester Multi-Vendor Online Grocery Management System

A high-severity improper authorization vulnerability (CVE-2026-14690) in the `save_users` function of SourceCodester Multi-Vendor Online Grocery Management System 1.0 allows remote unauthenticated attackers to manipulate user accounts, potentially leading to privilege escalation or unauthorized access, with a public exploit readily available.

Multi-Vendor Online Grocery Management System 1.0 vulnerability web-application improper-authorization cve sourcecodester
3t 1c
high advisory

Suspicious ICMP Redirect Messages from Internal Hosts Indicating MITM Activity

This brief details the detection of ICMP Redirect messages (IPv4 type 5, IPv6 type 137) originating from internal IP addresses, which strongly indicates Adversary-in-the-Middle (MITM) activity designed to manipulate routing, potentially leading to credential access or data exfiltration by directing target host traffic through a compromised internal system.

network-security credential-access mitm icmp
1r 1t
medium advisory

Detection of Deprecated TLS Version or Weak Cipher Negotiated Externally

This rule identifies successful outbound TLS sessions initiated by internal hosts to external destinations that utilize deprecated protocol versions (SSLv3, TLS 1.0, TLS 1.1) or weak cipher suites such as RC4, 3DES, NULL, EXPORT, or anonymous Diffie-Hellman. Such negotiations can indicate an Adversary-in-the-Middle attack or communication with legacy malware, allowing for traffic interception or decryption. Detection engineers should investigate the `source.ip`, `destination.ip`, `tls.version`, and `tls.cipher` to determine if the destination is a legitimate legacy system or a potential compromise, checking for concurrent alerts on the source host.

network tls credential-access command-and-control mitm downgrade weak-cipher
1r 2t
high advisory

CVE-2026-14688: Remote SQL Injection in itsourcecode Online Hotel Management System

A high-severity SQL injection vulnerability, CVE-2026-14688, exists in itsourcecode Online Hotel Management System 1.0 within the `/admin/login.php` file via the `email` argument, allowing remote unauthenticated attackers to bypass authentication and potentially exfiltrate data, with a publicly available exploit.

Online Hotel Management System 1.0 sql-injection web-vulnerability cve remote-code-execution data-exfiltration webserver
1r 1t 1c 3i
medium advisory

Potential DHCP Starvation via High Client MAC Cardinality

Attackers utilize DHCP starvation by flooding network segments with DHCP DISCOVER messages containing a high cardinality of distinct client MAC addresses to exhaust the DHCP lease pool, potentially leading to denial of service for legitimate clients and facilitating rogue DHCP server deployment.

network-attack denial-of-service network-security-monitoring impact
1t