6.9

CVSS4.0

CVE-2026-2199 - code-projects Online Reviewer System user-delete.php sql injection

A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated re…

πŸ“… Published: Feb. 9, 2026, 12:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 12:32 a.m.

6.9

CVSS4.0

CVE-2026-2198 - code-projects Online Reviewer System loaddata.php sql injection

A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack rem…

πŸ“… Published: Feb. 9, 2026, 12:32 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 12:32 a.m.

6.9

CVSS4.0

CVE-2026-2197 - code-projects Online Reviewer System exam-delete.php sql injection

A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injection. It is possible to initiate the attack remotely. The expl…

πŸ“… Published: Feb. 9, 2026, 12:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 12:02 a.m.

6.9

CVSS4.0

CVE-2026-2196 - code-projects Online Reviewer System exam-update.php sql injection

A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sql injection. The attack may be performed from remote. The ex…

πŸ“… Published: Feb. 9, 2026, 12:02 a.m. πŸ”„ Last Modified: Feb. 9, 2026, 12:02 a.m.

6.9

CVSS4.0

CVE-2026-2195 - code-projects Online Reviewer System questions-view.php sql injection

A vulnerability has been found in code-projects Online Reviewer System 1.0. This vulnerability affects unknown code of the file /system/system/admins/assessments/pretest/questions-view.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely…

πŸ“… Published: Feb. 8, 2026, 11:32 p.m. πŸ”„ Last Modified: Feb. 8, 2026, 11:32 p.m.

5.3

CVSS4.0

CVE-2026-2194 - D-Link DI-7100G C1 start_proxy_client_email command injection

A flaw has been found in D-Link DI-7100G C1 24.04.18D1. This affects the function start_proxy_client_email. Executing a manipulation can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used.

πŸ“… Published: Feb. 8, 2026, 11:32 p.m. πŸ”„ Last Modified: Feb. 8, 2026, 11:32 p.m.

5.3

CVSS4.0

CVE-2026-2193 - D-Link DI-7100G C1 set_jhttpd_info command injection

A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack is possible.

πŸ“… Published: Feb. 8, 2026, 11:02 p.m. πŸ”„ Last Modified: Feb. 8, 2026, 11:02 p.m.

8.6

CVSS4.0

CVE-2026-2192 - Tenda AC9 formGetRebootTimer stack-based overflow

A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys.schedulereboot.start_time/sys.schedulereboot.end_time leads to stack-based buffer overflow. The attack may be launched …

πŸ“… Published: Feb. 8, 2026, 11:02 p.m. πŸ”„ Last Modified: Feb. 8, 2026, 11:02 p.m.

8.6

CVSS4.0

CVE-2026-2191 - Tenda AC9 formGetDdosDefenceList stack-based overflow

A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could b…

πŸ“… Published: Feb. 8, 2026, 10:32 p.m. πŸ”„ Last Modified: Feb. 8, 2026, 10:32 p.m.

6.9

CVSS4.0

CVE-2026-2190 - itsourcecode School Management System controller.php sql injection

A security flaw has been discovered in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/user/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the publi…

πŸ“… Published: Feb. 8, 2026, 10:32 p.m. πŸ”„ Last Modified: Feb. 8, 2026, 10:32 p.m.
Total resulsts: 331616
Page 1 of 33,162
Β» next page
Filters