5.3
CVE-2026-7469 - Tenda 4G300 DelFil sub_425A28 command injection
A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
6.9
CVE-2026-7468 - 1024-lab smart-admin Demo Site index.html access control
A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been …
5.3
CVE-2026-7447 - SourceCodester Pet Grooming Management Software update_customer.php sql injection
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the argument type/length/business parameter validity causes sql injection. The attack is possible to be carried out remo…
6.9
CVE-2026-7446 - VetCoders mcp-server-semgrep MCP index.ts create_rule os command injection
A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command i…
5.4
CVE-2026-36756 -
A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
6.1
CVE-2026-38939 - XSS Allowing Remote Code Execution in Andrewtch88 MVC‑Ecommerce 1.0
Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component
6.1
CVE-2026-38940 - Cross‑Site Scripting in RafyMrX TOKO‑ONLINE‑ROTI Detail Page Enabling Client‑Side Code Execution
Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component
8.8
CVE-2026-36960 - Cross‑Site Request Forgery in U‑SPEED N300 Router Web Management Interface
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft …
6.1
CVE-2026-36763 - Stored XSS in SpringBlade 4.8.0 Notice Submit Endpoint
A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter.
5.9
CVE-2026-40684 - Denial of Service via malformed DNS PTR records exploits dn_expand bug in Exim on musl systems
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.