8.7

CVSS4.0

CVE-2026-7748 - Totolink N300RH POST Request cstecgi.cgi setUpgradeFW buffer overflow

A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument FileName can lead to buffer overflow. The attack can be launched re…

πŸ“… Published: May 4, 2026, 8:30 a.m. πŸ”„ Last Modified: May 4, 2026, 11 a.m.

9.3

CVSS4.0

CVE-2026-7747 - Totolink N300RH Parameter cstecgi.cgi loginauth buffer overflow

A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument Password results in buffer overflow. The attack can be init…

πŸ“… Published: May 4, 2026, 8:15 a.m. πŸ”„ Last Modified: May 4, 2026, 12:43 p.m.

5.3

CVSS4.0

CVE-2026-7746 - SourceCodester Web-based Pharmacy Product Management System edit-admin.php sql injection

A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /product_expiry/edit-admin.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is pu…

πŸ“… Published: May 4, 2026, 8 a.m. πŸ”„ Last Modified: May 4, 2026, 10 a.m.

5.3

CVSS4.0

CVE-2026-7745 - CodeAstro Online Classroom facultydetails sql injection

A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineClassroom/facultydetails. This manipulation of the argument deleteid causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed an…

πŸ“… Published: May 4, 2026, 7:45 a.m. πŸ”„ Last Modified: May 4, 2026, 10 a.m.

9.8

CVSS3.1

CVE-2025-14320 - XSS in Tegsoft's Online Support Application

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allows Reflected XSS. This issue affects Online Support Application: from V3 through 31122025.

πŸ“… Published: May 4, 2026, 7:41 a.m. πŸ”„ Last Modified: May 4, 2026, 4:06 p.m.

5.3

CVSS4.0

CVE-2026-7744 - CodeAstro Online Classroom addnewstudent sql injection

A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipulation of the argument fname results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

πŸ“… Published: May 4, 2026, 7:30 a.m. πŸ”„ Last Modified: May 4, 2026, 8:30 a.m.

5.3

CVSS4.0

CVE-2026-7743 - CodeAstro Online Classroom studentdetails sql injection

A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdetails. The manipulation of the argument deleteid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclo…

πŸ“… Published: May 4, 2026, 7:15 a.m. πŸ”„ Last Modified: May 5, 2026, 12:58 a.m.

5.3

CVSS4.0

CVE-2026-7742 - CodeAstro Online Classroom facultylogin sql injection

A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /OnlineClassroom/facultylogin. Executing a manipulation of the argument fid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

πŸ“… Published: May 4, 2026, 7 a.m. πŸ”„ Last Modified: May 4, 2026, 11:30 a.m.

5.3

CVSS4.0

CVE-2026-7741 - CodeAstro Online Classroom studentlogin sql injection

A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/studentlogin. Performing a manipulation of the argument sid results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

πŸ“… Published: May 4, 2026, 6:45 a.m. πŸ”„ Last Modified: May 4, 2026, 12:46 p.m.

4.8

CVSS4.0

CVE-2026-7740 - justdan96 tsMuxer vvc.cpp setFPS denial of service

A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit::setFPS of the file tsMuxer/vvc.cpp. Such manipulation of the argument track_id leads to denial of service. An attack has to be approached locally. The exploit has been disclosed …

πŸ“… Published: May 4, 2026, 6:30 a.m. πŸ”„ Last Modified: May 4, 2026, 6:30 a.m.
Total resulsts: 349182
Page 136 of 34,919
Β« previous page Β» next page
Filters