6.9

CVSS4.0

CVE-2026-2189 - itsourcecode School Management System index.php sql injection

A vulnerability was identified in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/report/index.php. The manipulation of the argument ay leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

πŸ“… Published: Feb. 8, 2026, 10:02 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

8.6

CVSS4.0

CVE-2026-2188 - UTT 进取 521G formPdbUpConfig sub_446B18 os command injection

A vulnerability was determined in UTT 进取 521G 3.1.1-190816. The impacted element is the function sub_446B18 of the file /goform/formPdbUpConfig. Executing a manipulation of the argument policyNames can lead to os command injection. It is possible to launch the attack remotely. The exploit has been …

πŸ“… Published: Feb. 8, 2026, 9:32 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

8.7

CVSS4.0

CVE-2026-2187 - Tenda RX3 formSetQosBand set_qosMib_list stack-based overflow

A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been ma…

πŸ“… Published: Feb. 8, 2026, 9:02 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

8.7

CVSS4.0

CVE-2026-2186 - Tenda RX3 SetIpMacBind fromSetIpMacBind stack-based overflow

A vulnerability has been found in Tenda RX3 16.03.13.11. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument list leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and…

πŸ“… Published: Feb. 8, 2026, 9:02 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

8.7

CVSS4.0

CVE-2026-2185 - Tenda RX3 MAC Filtering Configuration Endpoint setBlackRule set_device_name stack-based overflow

A flaw has been found in Tenda RX3 16.03.13.11. This issue affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. This manipulation of the argument devName/mac causes stack-based buffer overflow. The attack is possible to be carr…

πŸ“… Published: Feb. 8, 2026, 8:32 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

6.9

CVSS4.0

CVE-2026-2184 - Great Developers Certificate Generation System csv.php os command injection

A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This vulnerability affects unknown code of the file /restructured/csv.php. The manipulation of the argument photo results in os command injection. The attack can be execute…

πŸ“… Published: Feb. 8, 2026, 8:32 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

5.3

CVSS4.0

CVE-2026-2183 - Great Developers Certificate Generation System csv.php unrestricted upload

A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. …

πŸ“… Published: Feb. 8, 2026, 8:02 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

8.6

CVSS4.0

CVE-2026-2182 - UTT 进取 521G setSysAdm doSystem command injection

A weakness has been identified in UTT 进取 521G 3.1.1-190816. Affected by this issue is the function doSystem of the file /goform/setSysAdm. Executing a manipulation of the argument passwd1 can lead to command injection. The attack may be launched remotely. The exploit has been made available to the …

πŸ“… Published: Feb. 8, 2026, 8:02 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

8.7

CVSS4.0

CVE-2026-2181 - Tenda RX3 openSchedWifi stack-based overflow

A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. The attack may be initiated remot…

πŸ“… Published: Feb. 8, 2026, 7:32 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 5:09 p.m.

8.7

CVSS4.0

CVE-2026-2180 - Tenda RX3 fast_setting_wifi_set stack-based overflow

A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation of the argument ssid_5g leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be use…

πŸ“… Published: Feb. 8, 2026, 7:32 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 5:12 p.m.
Total resulsts: 331696
Page 10 of 33,170
Β« previous page Β» next page
Filters