A vulnerability was found in SourceCodester Online Class Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/message/search.php. Executing a manipulation of the argument term can lead to sql injection.
This vulnerability is handled as CVE-2026-2090. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability has been found in SourceCodester Online Class Record System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/subject/controller.php. Performing a manipulation of the argument ID results in sql injection.
This vulnerability is known as CVE-2026-2089. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Infosecurity Europe 2026 will debut a new Cyber Startup Programme, featuring a dedicated show-floor zone for early-stage cybersecurity companies to showcase innovations, connect with investors and highlight emerging technologies
A vulnerability, which was classified as critical, was found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection.
This vulnerability is traded as CVE-2026-2088. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection.
This vulnerability appears as CVE-2026-2087. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability classified as critical was found in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formFireWall of the component Management Interface. The manipulation of the argument GroupName results in buffer overflow.
This vulnerability is reported as CVE-2026-2086. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical has been found in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to command injection.
This vulnerability is documented as CVE-2026-2085. The attack can be initiated remotely. Additionally, an exploit exists.