4.8

CVSS4.0

CVE-2026-2156 - code-projects Online Student Management System Announcement Management index.php cross site scripti…

A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown function of the file /admin/announcement/index.php?view=add of the component Announcement Management Module. This manipulation causes cross site scripting. The attack is possible…

📅 Published: Feb. 8, 2026, 2:32 p.m. 🔄 Last Modified: April 18, 2026, 6:30 p.m.

8.6

CVSS4.0

CVE-2026-2155 - D-Link DIR-823X Configuration set_dmz sub_4208A0 os command injection

A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument dmz_host/dmz_enable results in os command injection. The attack can be executed remotel…

📅 Published: Feb. 8, 2026, 2:02 p.m. 🔄 Last Modified: April 17, 2026, 10 p.m.

5.3

CVSS4.0

CVE-2026-2154 - SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System Patient Registration reg…

A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impacted is an unknown function of the file /registration.php of the component Patient Registration Module. The manipulation of the argument First Name leads to cross site scripting. Re…

📅 Published: Feb. 8, 2026, 1:32 p.m. 🔄 Last Modified: April 17, 2026, 10 p.m.

5.3

CVSS4.0

CVE-2026-2153 - mwielgoszewski doorman views.py is_safe_url redirect

A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been publicly disclosed a…

📅 Published: Feb. 8, 2026, 1:02 p.m. 🔄 Last Modified: April 17, 2026, 10 p.m.

8.6

CVSS4.0

CVE-2026-2152 - D-Link DIR-615 Web Configuration adv_routing.php os command injection

A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/ submask/ gw results in os command injection. The attack may be initiated remotely. T…

📅 Published: Feb. 8, 2026, 12:32 p.m. 🔄 Last Modified: April 18, 2026, 1:30 p.m.

8.6

CVSS4.0

CVE-2026-2151 - D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection

A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr  leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the…

📅 Published: Feb. 8, 2026, 12:02 p.m. 🔄 Last Modified: April 17, 2026, 10 p.m.

5.3

CVSS4.0

CVE-2026-2150 - SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System checkin.php cross site s…

A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /checkin.php. This manipulation of the argument patient_id causes cross site scripting. The attack can be initiated remotely. The…

📅 Published: Feb. 8, 2026, 11:32 a.m. 🔄 Last Modified: April 18, 2026, 1:30 p.m.

5.3

CVSS4.0

CVE-2026-2149 - SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System appointments.php cross s…

A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /appointments.php. The manipulation of the argument patient_id results in cross site scripting. It is possible to la…

📅 Published: Feb. 8, 2026, 11:02 a.m. 🔄 Last Modified: April 18, 2026, 1:30 p.m.

6.9

CVSS4.0

CVE-2026-2148 - Tenda AC21 Web Management DownloadFlash information disclosure

A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been …

📅 Published: Feb. 8, 2026, 10:32 a.m. 🔄 Last Modified: April 17, 2026, 10 p.m.

6.9

CVSS4.0

CVE-2026-2147 - Tenda AC21 Web Management DownloadLog information disclosure

A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Management Interface. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. The exploit has been made avai…

📅 Published: Feb. 8, 2026, 10:02 a.m. 🔄 Last Modified: April 17, 2026, 10 p.m.
Total resulsts: 348419
Page 1674 of 34,842
« previous page » next page
Filters