CVE-2026-90787High· 7.3▾ MidnightPoC availableA vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow.…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
0.4%
A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94048Medium· 6.6A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0
CVE-2026-94047Medium· 6.3A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32
CVE-2026-90856High· 7.3A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0
CVE-2026-90501Medium· 6.3A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT
CVE-2026-90523High· 7.3A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09
CVE-2026-85513Medium· 6.3StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management