CVE-2026-0699
published 2026-01-08CVE-2026-0699: A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file…
PriorityP346high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.31%
23.2th percentile
A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| carmelo | intern_membership_management_system | — | — |
| code-projects | intern_membership_management_system | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.0LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.8MEDIUMAV:N/AC:L/Au:M/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wfh3-rv4c-xphx: A vulnerability was found in code-projects Intern Membership Management System 1
ghsa_unreviewed·2026-01-08
CVE-2026-0699 [MEDIUM] CWE-74 GHSA-wfh3-rv4c-xphx: A vulnerability was found in code-projects Intern Membership Management System 1
A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Red Hat
vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion
vendor_redhat·2026-06-25·CVSS 7.8
CVE-2026-57456 [HIGH] CWE-94 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion
vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
There is a security flaw in Vim. If you use Vim to open a malicious file written by a hacker, and you use the auto-comp
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-57456 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion [fedora-all]
bugzilla·2026-07-03·CVSS 7.8
CVE-2026-57456 [HIGH] CVE-2026-57456 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion [fedora-all]
CVE-2026-57456 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out
Bugzilla
CVE-2026-57456 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion
bugzilla·2026-06-25·CVSS 7.8
CVE-2026-57456 [HIGH] CVE-2026-57456 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion
CVE-2026-57456 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
2026-01-08
Published