9.8
CVE-2026-26704 -
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.
4.9
CVE-2026-26698 - Simple Student Alumni System v1.0 SQL Injection in TracerStudy/modal_edit.php
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.
9.8
CVE-2026-24110 - Buffer Overflow via Overly Long addDhcpRules Input in Tenda W20E Firmware
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule, " %d\t%[^\t]\t%[^\n\r\t]", &dhcpsIndex, dhcpsIP, dhcpsMac);`, the lack of size validation for the โฆ
9.8
CVE-2026-26712 - SQL Injection in Simple Food Order System Admin Ticket View Endpoint
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.
9.8
CVE-2026-24115 - Buffer Overflow in Tenda W20E Firmware via Improper Size Validation
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstruleQos` may lead to buffer overflow.
6.1
CVE-2025-66880 -
Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute arbitrary code via the LoginComp (Module 2093) and SignupComp (Module 2094) modules.
7.5
CVE-2025-70252 -
An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.
9.8
CVE-2026-24101 - Command Injection in Tenda AC15 Router FormSetIptv
An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.
7.5
CVE-2026-24114 - Buffer Overflow via Unvalidated Port Mapping Index in Tenda W20E Firmware
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`.
9.8
CVE-2026-24107 - Critical Command Injection via USB Partition Parameter in Tenda W20E Router
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities.