A vulnerability marked as problematic has been reported in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Performing a manipulation of the argument page results in cross site scripting.
This vulnerability is reported as CVE-2026-3702. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability labeled as critical has been found in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function Edit_BasicSSID_5G of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow.
This vulnerability is documented as CVE-2026-3701. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability identified as critical has been detected in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigDnsFilterGlobal. This manipulation causes buffer overflow.
This vulnerability is registered as CVE-2026-3700. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability categorized as critical has been discovered in UTT HiPER 810G up to 1.7.7-171114. This impacts the function strcpy of the file /goform/formRemoteControl. The manipulation results in buffer overflow.
This vulnerability is cataloged as CVE-2026-3699. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in UTT HiPER 810G up to 1.7.7-171114. It has been rated as critical. This affects the function strcpy of the file /goform/NTP. The manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2026-3698. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in Planet ICG-2510 1.0_20250811. It has been declared as critical. The impacted element is the function sub_40C8E4 of the file /usr/sbin/httpd of the component Language Package Configuration Handler. Executing a manipulation of the argument Language can lead to stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-3697. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. It has been classified as critical. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation results in os command injection.
This vulnerability is identified as CVE-2026-3696. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in SourceCodester Modern Image Gallery App 1.0 and classified as critical. Impacted is an unknown function of the file /delete.php. Such manipulation of the argument filename leads to path traversal.
This vulnerability is referenced as CVE-2026-3695. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability has been found in Shy2593666979 AgentChat up to 2.3.0 and classified as critical. This issue affects the function get_user_info/update_user_info of the file /src/backend/agentchat/api/v1/user.py of the component User Endpoint. This manipulation of the argument user_id causes improper control of resource identifiers.
The identification of this vulnerability is CVE-2026-3693. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.