6.9

CVSS4.0

CVE-2026-2211 - code-projects Online Music Site AdminDeleteCategory.php sql injection

A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCategory.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly di…

πŸ“… Published: Feb. 9, 2026, 2:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 2:32 a.m.

8.6

CVSS4.0

CVE-2026-2210 - D-Link DIR-823X set_filtering sub_4211C8 os command injection

A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Feb. 9, 2026, 2:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 2:02 a.m.

8.7

CVSS4.0

CVE-2026-2203 - Tenda AC8 Embedded Httpd Service fast_setting_wifi_set buffer overflow

A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the argument timeZone causes buffer overflow. Remote exploitation of the attack is possi…

πŸ“… Published: Feb. 9, 2026, 2:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 2:02 a.m.

8.7

CVSS4.0

CVE-2026-2202 - Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow

A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit is now public and m…

πŸ“… Published: Feb. 9, 2026, 1:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 1:32 a.m.

4.8

CVSS4.0

CVE-2026-2201 - ZeroWdd studentmanager LeaveController.java addLeave cross site scripting

A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanager/controller/LeaveController.java. The manipulation of the argument Reason for Leave leads to cross …

πŸ“… Published: Feb. 9, 2026, 1:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 1:02 a.m.

4.8

CVSS4.0

CVE-2026-2200 - heyewei JFinalCMS API Endpoint save cross site scripting

A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/save of the component API Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public …

πŸ“… Published: Feb. 9, 2026, 1:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 1:02 a.m.

6.9

CVSS4.0

CVE-2026-2199 - code-projects Online Reviewer System user-delete.php sql injection

A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated re…

πŸ“… Published: Feb. 9, 2026, 12:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 12:32 a.m.

6.9

CVSS4.0

CVE-2026-2198 - code-projects Online Reviewer System loaddata.php sql injection

A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack rem…

πŸ“… Published: Feb. 9, 2026, 12:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 12:32 a.m.

6.9

CVSS4.0

CVE-2026-2197 - code-projects Online Reviewer System exam-delete.php sql injection

A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injection. It is possible to initiate the attack remotely. The expl…

πŸ“… Published: Feb. 9, 2026, 12:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 12:02 a.m.

6.9

CVSS4.0

CVE-2026-2196 - code-projects Online Reviewer System exam-update.php sql injection

A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sql injection. The attack may be performed from remote. The ex…

πŸ“… Published: Feb. 9, 2026, 12:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 12:02 a.m.
Total resulsts: 331662
Page 5 of 33,167
Β« previous page Β» next page
Filters