5.3

CVSS4.0

CVE-2026-2109 - jsbroks COCO Annotator Delete Category undo improper authorization

A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. The attack may be launched remotely. The exploit is publicly …

πŸ“… Published: Feb. 7, 2026, 7:32 p.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

6.9

CVSS4.0

CVE-2026-2108 - jsbroks COCO Annotator Endpoint long_task denial of service

A vulnerability was determined in jsbroks COCO Annotator up to 0.11.1. This impacts an unknown function of the file /api/info/long_task of the component Endpoint. This manipulation causes denial of service. The attack may be initiated remotely. The exploit has been publicly disclosed and may be uti…

πŸ“… Published: Feb. 7, 2026, 7:02 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 p.m.

5.3

CVSS4.0

CVE-2026-2107 - yeqifu warehouse Log Info LoginfoController.java batchDeleteLoginfo improper authorization

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDeleteLoginfo of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\LoginfoController.java of the component Log Info Handle…

πŸ“… Published: Feb. 7, 2026, 6:32 p.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

5.3

CVSS4.0

CVE-2026-2106 - yeqifu warehouse Notice Management NoticeController.java batchDeleteNotice improper authorization

A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/deleteNotice/batchDeleteNotice of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\NoticeController.java of the comp…

πŸ“… Published: Feb. 7, 2026, 5:32 p.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

5.3

CVSS4.0

CVE-2026-2105 - yeqifu warehouse Department Management DeptController.java deleteDept improper authorization

A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\DeptController.java of the component Department Management. Execut…

πŸ“… Published: Feb. 7, 2026, 5:02 p.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

6.9

CVSS4.0

CVE-2026-2090 - SourceCodester Online Class Record System search.php sql injection

A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown processing of the file /admin/message/search.php. Executing a manipulation of the argument term can lead to sql injection. The attack can be executed remotely. The exploit has been publi…

πŸ“… Published: Feb. 7, 2026, 3:32 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 p.m.

6.9

CVSS4.0

CVE-2026-2089 - SourceCodester Online Class Record System controller.php sql injection

A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of the file /admin/subject/controller.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been m…

πŸ“… Published: Feb. 7, 2026, 3:02 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 p.m.

6.9

CVSS4.0

CVE-2026-2088 - PHPGurukul Beauty Parlour Management System accepted-appointment.php sql injection

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the pub…

πŸ“… Published: Feb. 7, 2026, 2:32 p.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

6.9

CVSS4.0

CVE-2026-2087 - SourceCodester Online Class Record System login.php sql injection

A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection. The attack may be initiated remotely. The exploit has been published and may …

πŸ“… Published: Feb. 7, 2026, 2:02 p.m. πŸ”„ Last Modified: April 17, 2026, 10:15 p.m.

8.7

CVSS4.0

CVE-2026-2086 - UTT HiPER 810G Management formFireWall strcpy buffer overflow

A vulnerability was detected in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formFireWall of the component Management Interface. The manipulation of the argument GroupName results in buffer overflow. The attack can be launched remotely…

πŸ“… Published: Feb. 7, 2026, 1:32 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 p.m.
Total resulsts: 349182
Page 1756 of 34,919
Β« previous page Β» next page
Filters