Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-13501

antlr ANTLR4 gofmt GoTarget.java GoTarget command injection_CVE-2026-13501

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/s...

antlr ANTLR4 4.13.0 CVE
MEDIUM 6.9 CVE-2026-13498

yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection_CVE-2026-13498

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php o...

yashpokharna2555 restaurent-management-system 5f3eca87cb681366866a78038af17891c4c86612 CVE
MEDIUM 5.3 CVE-2026-13497

itsourcecode Hospital Management System appointment.php sql injection_CVE-2026-13497

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-13499

yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting_CVE-2026-13499

A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.p...

yashpokharna2555 restaurent-management-system 5f3eca87cb681366866a78038af17891c4c86612 CVE
MEDIUM 6.9 CVE-2026-13500

antlr ANTLR4 Grammar Action Block OutputFile.java code injection_CVE-2026-13500

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/Output...

antlr ANTLR4 4.13.0 CVE
MEDIUM 6.3 CVE-2026-13491

78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service_CVE-2026-13491

A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/pro...

78 xiaozhi-esp32 2.2.0 CVE
MEDIUM 6.3 CVE-2026-13490

glpi-project glpi Document document.send.php canViewFile authorization_CVE-2026-13490

A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file f...

glpi-project glpi 11.0.5 CVE
MEDIUM 5.3 CVE-2026-13496

itsourcecode Hospital Management System ajaxmedicine.php sql injection_CVE-2026-13496

A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 5.1 CVE-2026-13495

itsourcecode Hospital Management System adminprofile.php sql injection_CVE-2026-13495

A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The m...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 6.9 CVE-2026-13486

SourceCodester Class and Exam Timetabling System preview6.php sql injection_CVE-2026-13486

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview...

SourceCodester Class and Exam Timetabling System 1.0 CVE