2.1

CVSS4.0

CVE-2025-66606 -

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HM…

πŸ“… Published: Feb. 9, 2026, 3:06 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

6.9

CVSS4.0

CVE-2026-2212 - code-projects Online Music Site AdminEditCategory.php sql injection

A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Administrator/PHP/AdminEditCategory.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The …

πŸ“… Published: Feb. 9, 2026, 3:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:20 p.m.

6.9

CVSS4.0

CVE-2026-2211 - code-projects Online Music Site AdminDeleteCategory.php sql injection

A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCategory.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly di…

πŸ“… Published: Feb. 9, 2026, 2:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:24 p.m.

8.6

CVSS4.0

CVE-2026-2210 - D-Link DIR-823X set_filtering sub_4211C8 os command injection

A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Feb. 9, 2026, 2:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:41 p.m.

8.7

CVSS4.0

CVE-2026-2203 - Tenda AC8 Embedded Httpd Service fast_setting_wifi_set buffer overflow

A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the argument timeZone causes buffer overflow. Remote exploitation of the attack is possi…

πŸ“… Published: Feb. 9, 2026, 2:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:37 p.m.

8.7

CVSS4.0

CVE-2026-2202 - Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow

A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit is now public and m…

πŸ“… Published: Feb. 9, 2026, 1:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:37 p.m.

4.8

CVSS4.0

CVE-2026-2201 - ZeroWdd studentmanager LeaveController.java addLeave cross site scripting

A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanager/controller/LeaveController.java. The manipulation of the argument Reason for Leave leads to cross …

πŸ“… Published: Feb. 9, 2026, 1:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:36 p.m.

4.8

CVSS4.0

CVE-2026-2200 - heyewei JFinalCMS API Endpoint save cross site scripting

A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/save of the component API Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public …

πŸ“… Published: Feb. 9, 2026, 1:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:35 p.m.

6.9

CVSS4.0

CVE-2026-2199 - code-projects Online Reviewer System user-delete.php sql injection

A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated re…

πŸ“… Published: Feb. 9, 2026, 12:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:34 p.m.

6.9

CVSS4.0

CVE-2026-2198 - code-projects Online Reviewer System loaddata.php sql injection

A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack rem…

πŸ“… Published: Feb. 9, 2026, 12:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.
Total resulsts: 331695
Page 8 of 33,170
Β« previous page Β» next page
Filters