← Back to the live CVE advisory feed

CVE-2026-94034: Product identification pending

Severity
2 (LOW)
Patch status
Unknown
Published
2026-09-20T15:16:30.730
Modified
2026-09-20T15:16:30.730

Why it matters

This matters because the affected product may allow code execution. Prioritize systems that are internet-facing or have privileged access to other infrastructure.

Recommended admin actions

  • Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
  • Treat internet-facing systems as higher priority.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 21, 2026 04:00 AM UTC
109 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-90817
REDCap PATCH
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-88856
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-88857
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-94003
CF-N1-S
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-88854
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-94089
DIR-868L
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94097
NBR200V2
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94107
nivocart
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-86553
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-94104
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94106
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94109
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-88855
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-94095
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94096
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94099
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94100
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94101
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-87067
Forminator Forms PATCH
Reporter: CONTACT
8.5
HIGH
VIEW RECORD
CVE-2026-94098
NBR200V2
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-94128
VIVID LED DJ
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-94129
VALKYRIE AURORA
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-94108
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-82842
SAML Single Sign On PATCH
Reporter: CONTACT
8.1
HIGH
VIEW RECORD
CVE-2026-94112
Product identification pending PATCH
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-85017
Unlimited Elements For Elementor PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-87839
Tripzzy PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-94036
DIR-X1860
Reporter: CNA
7.4
HIGH
VIEW RECORD
CVE-2026-81650
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
7.2
HIGH
VIEW RECORD
CVE-2026-92540
Import and export users and customers PATCH
Reporter: CONTACT
7.2
HIGH
VIEW RECORD
CVE-2026-92541
Import and export users and customers PATCH
Reporter: CONTACT
7.2
HIGH
VIEW RECORD
CVE-2026-94113
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-93961
UJCMS
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-93969
SxDevOps
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-93970
SxDevOps
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-93971
SxDevOps
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-94105
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-94111
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-92254
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
6.9
MEDIUM
VIEW RECORD
CVE-2026-14844
Master Slider
Reporter: CONTACT
6.8
MEDIUM
VIEW RECORD
CVE-2026-84223
Kirki PATCH
Reporter: CONTACT
6.8
MEDIUM
VIEW RECORD
CVE-2026-94185
Product identification pending PATCH
Reporter: 7FFCEE3D-2C14-4C3E-B844-86C6A321A158
6.7
MEDIUM
VIEW RECORD
CVE-2026-87068
Forminator Forms PATCH
Reporter: CONTACT
6.6
MEDIUM
VIEW RECORD
CVE-2026-92422
Meow Gallery PATCH
Reporter: CONTACT
6.5
MEDIUM
VIEW RECORD
CVE-2026-86555
Product identification pending
Reporter: PSIRT
6.2
MEDIUM
VIEW RECORD
CVE-2026-92252
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
5.9
MEDIUM
VIEW RECORD
CVE-2026-93962
Kamailio PATCH
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93964
nginx-proxy-manager
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93972
Online Reviewer Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93973
Online Reviewer Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93974
Online Reviewer Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93978
Internship Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93979
Internship Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93980
Internship Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93997
Drug Recommendation System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94004
DedeCMS
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94015
Drug Recommendation System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94038
dim-sum-app
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94039
TaxHacker
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94040
TaxHacker
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94043
Free5GC
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94044
MCP
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94110
QCMS
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86552
Product identification pending
Reporter: PSIRT
5.4
MEDIUM
VIEW RECORD
CVE-2026-87840
Tripzzy PATCH
Reporter: CONTACT
5.3
MEDIUM
VIEW RECORD
CVE-2026-94050
DIR-X1860Z PATCH
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-94090
Manalyze
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-92253
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
5.2
MEDIUM
VIEW RECORD
CVE-2026-93965
SxDevOps
Reporter: CNA
5.1
MEDIUM
VIEW RECORD
CVE-2026-93966
SxDevOps
Reporter: CNA
5.1
MEDIUM
VIEW RECORD
CVE-2026-93967
SxDevOps
Reporter: CNA
5.1
MEDIUM
VIEW RECORD
CVE-2026-93968
SxDevOps
Reporter: CNA
5.1
MEDIUM
VIEW RECORD
CVE-2026-92410
Sign-up Sheets PATCH
Reporter: CONTACT
4.3
MEDIUM
VIEW RECORD
CVE-2026-86554
Product identification pending
Reporter: PSIRT
4.3
MEDIUM
VIEW RECORD
CVE-2026-81653
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
4.2
MEDIUM
VIEW RECORD
CVE-2026-16542
Import and export users and customers PATCH
Reporter: CONTACT
4.1
MEDIUM
VIEW RECORD
CVE-2026-92965
TikTok PATCH
Reporter: CONTACT
3.7
LOW
VIEW RECORD
CVE-2026-81651
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
3.1
LOW
VIEW RECORD
CVE-2026-81654
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
3.1
LOW
VIEW RECORD
CVE-2026-81652
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
2.7
LOW
VIEW RECORD
CVE-2026-92423
Product identification pending PATCH
Reporter: CONTACT
2.7
LOW
VIEW RECORD
CVE-2026-93960
Pixelfed PATCH
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-93963
Leave Management System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94028
Product identification pending
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94031
Product identification pending
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94032
Leave Management System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94035
Drug Recommendation System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94037
mcp-file-analyzer
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94041
Restaurant-Management-System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94042
Restaurant Management System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94046
Product identification pending
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94047
Product identification pending
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94049
Product identification pending
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94051
Product identification pending
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94093
Product identification pending
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94094
Product identification pending
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94102
WuzhiCMS
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-93977
Assessment Management
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94033
Product identification pending
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94034
Product identification pending
Reporter: CNA
2
LOW
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.