5.1

CVSS4.0

CVE-2026-7697 - AMTT Hotel Broadband Operation System cardhand_submit.php sql injection

A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected is an unknown function of the file /manager/card/cardhand_submit.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclos…

📅 Published: May 3, 2026, 1:15 p.m. 🔄 Last Modified: May 3, 2026, 9 p.m.

5.3

CVSS4.0

CVE-2026-7696 - Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform uploadH5Files unres…

A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remo…

📅 Published: May 3, 2026, 12:30 p.m. 🔄 Last Modified: May 4, 2026, 4:06 p.m.

6.9

CVSS4.0

CVE-2026-7695 - Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform elecMaxMinAvgValue …

A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be init…

📅 Published: May 3, 2026, 12:15 p.m. 🔄 Last Modified: May 4, 2026, 4:06 p.m.

6.9

CVSS4.0

CVE-2026-7694 - Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue …

A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impacted element is an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. Executing a manipulation of the argument fCircuitids can lead to sql injection. The attac…

📅 Published: May 3, 2026, 11:45 a.m. 🔄 Last Modified: May 5, 2026, 12:42 a.m.

5.3

CVSS4.0

CVE-2026-7692 - Wavlink WL-WN570HA1 adm.cgi ping_ddns command injection

A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS results in command injection. The attack can be initiated remotely. The exploit is now public and may …

📅 Published: May 3, 2026, 11 a.m. 🔄 Last Modified: May 7, 2026, 1:46 a.m.

5.3

CVSS4.0

CVE-2026-7691 - Wavlink WL-WN570HA1 adm.cgi set_sys_cmd command injection

A security vulnerability has been detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. Impacted is the function set_sys_cmd of the file /cgi-bin/adm.cgi. Such manipulation of the argument command leads to command injection. It is possible to launch the attack remotely. The exploit has been disclose…

📅 Published: May 3, 2026, 10:15 a.m. 🔄 Last Modified: May 7, 2026, 1:46 a.m.

5.3

CVSS4.0

CVE-2026-7690 - Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection

A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit has been made availab…

📅 Published: May 3, 2026, 9:45 a.m. 🔄 Last Modified: May 7, 2026, 1:42 a.m.

6.3

CVSS4.0

CVE-2026-7689 - Dolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verification

A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib.php of the component Online Signature Module. The manipulation results in improper verification of cryptographic signature. The at…

📅 Published: May 3, 2026, 9:30 a.m. 🔄 Last Modified: May 4, 2026, 4:06 p.m.

2.3

CVSS4.0

CVE-2026-7688 - Dolibarr ERP CRM Shipments API Endpoint expedition.class.php _checkValForAPI sql injection

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file htdocs/expedition/class/expedition.class.php of the component Shipments API Endpoint. The manipulation of the argument fields leads to sql injection. The attack is possible to be c…

📅 Published: May 3, 2026, 9:15 a.m. 🔄 Last Modified: May 4, 2026, 4:06 p.m.

5.3

CVSS4.0

CVE-2026-7687 - langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injecti…

A vulnerability was determined in langflow-ai langflow up to 1.8.4. Affected by this issue is the function CodeParser.parse_callable_details of the file src/lfx/src/lfx/custom/code_parser/code_parser.py of the component Full Builtins Module Handler. Executing a manipulation can lead to command inje…

📅 Published: May 3, 2026, 8:45 a.m. 🔄 Last Modified: May 5, 2026, 12:40 a.m.
Total resulsts: 349182
Page 145 of 34,919
« previous page » next page
Filters