CVE-2026-86215Medium· 4.3▾ TwilightPoC availableA vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to sessio…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Exploit / PoC code exists
A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86213High· 7.3A vulnerability was found in Mstfakts College-Management-System
CVE-2026-92800Medium· 6.8Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents
CVE-2026-87014Medium· 6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-19931Critical· 9.8A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials
CVE-2026-55513Medium· 5.4nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
CVE-2026-77519Medium· 5.4MaxKB is an open-source AI assistant for enterprise