CVE-2026-89178High· 8.8▾ TwilightWeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing stude…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89176High· 8.8WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability
CVE-2026-89177High· 8.8WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability
CVE-2026-89179Medium· 4.3WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability
CVE-2026-85125Medium· 5.4The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation
CVE-2026-73419Medium· 6.8NextAuth.js provides authentication for Next.js
CVE-2026-6734High· 7.5undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)