6.9

CVSS4.0

CVE-2026-2088 - PHPGurukul Beauty Parlour Management System accepted-appointment.php sql injection

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the pub…

πŸ“… Published: Feb. 7, 2026, 2:32 p.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

6.9

CVSS4.0

CVE-2026-2087 - SourceCodester Online Class Record System login.php sql injection

A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection. The attack may be initiated remotely. The exploit has been published and may …

πŸ“… Published: Feb. 7, 2026, 2:02 p.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

8.7

CVSS4.0

CVE-2026-2086 - UTT HiPER 810G Management formFireWall strcpy buffer overflow

A vulnerability was detected in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formFireWall of the component Management Interface. The manipulation of the argument GroupName results in buffer overflow. The attack can be launched remotely…

πŸ“… Published: Feb. 7, 2026, 1:32 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 p.m.

8.6

CVSS4.0

CVE-2026-2085 - D-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection

A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to command injection. The attack can be initiated remotely. The …

πŸ“… Published: Feb. 7, 2026, 12:02 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 p.m.

8.6

CVSS4.0

CVE-2026-2084 - D-Link DIR-823X set_language os command injection

A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to …

πŸ“… Published: Feb. 7, 2026, 11:32 a.m. πŸ”„ Last Modified: April 18, 2026, 1:30 p.m.

6.9

CVSS4.0

CVE-2026-2083 - code-projects Social Networking Site delete_post.php sql injection

A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the…

πŸ“… Published: Feb. 7, 2026, 10:32 a.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

5.1

CVSS4.0

CVE-2026-2082 - D-Link DIR-823X set_mac_clone os command injection

A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.

πŸ“… Published: Feb. 7, 2026, 10:02 a.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

5.1

CVSS4.0

CVE-2026-2081 - D-Link DIR-823X set_password os command injection

A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclos…

πŸ“… Published: Feb. 7, 2026, 9:32 a.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

8.6

CVSS4.0

CVE-2026-2080 - UTT HiPER 810 formUser setSysAdm command injection

A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and …

πŸ“… Published: Feb. 7, 2026, 9:02 a.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

5.3

CVSS4.0

CVE-2026-2079 - yeqifu warehouse Menu Management MenuController.java deleteMenu improper authorization

A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addMenu/updateMenu/deleteMenu of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\MenuController.java of the component Menu Management. Executing…

πŸ“… Published: Feb. 7, 2026, 8:32 a.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.
Total resulsts: 348395
Page 1678 of 34,840
Β« previous page Β» next page
Filters