A vulnerability described as problematic has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/save of the component API Endpoint. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-2200. The attack can be launched remotely. Moreover, an exploit is present.
Not everyone wants AI in their browser. Firefox 148 is introducing easy toggles to disable chatbots and AI tab grouping. Discover how Mozilla is prioritising user choice and privacy in its latest 2026 update.
A vulnerability marked as critical has been reported in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection.
This vulnerability is identified as CVE-2026-2199. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability labeled as critical has been found in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection.
This vulnerability is referenced as CVE-2026-2198. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability identified as critical has been detected in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injection.
The identification of this vulnerability is CVE-2026-2197. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability categorized as critical has been discovered in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sql injection.
This vulnerability was named CVE-2026-2196. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability was found in code-projects Online Reviewer System 1.0. It has been rated as critical. This vulnerability affects unknown code of the file /system/system/admins/assessments/pretest/questions-view.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-2195. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability was found in D-Link DI-7100G C1 24.04.18D1. It has been declared as critical. This affects the function start_proxy_client_email. Executing a manipulation can lead to command injection.
This vulnerability is handled as CVE-2026-2194. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability was found in D-Link DI-7100G C1 24.04.18D1. It has been classified as critical. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection.
This vulnerability is known as CVE-2026-2193. Remote exploitation of the attack is possible. No exploit is available.