A vulnerability labeled as critical has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/check. Such manipulation of the argument room_type leads to sql injection.
This vulnerability is traded as CVE-2026-7506. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability identified as critical has been detected in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization.
This vulnerability appears as CVE-2026-7505. The attack may be initiated remotely. In addition, an exploit is available.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument wepkey2 results in buffer overflow.
This vulnerability is reported as CVE-2026-7503. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in LinkStackOrg LinkStack up to 4.8.6. It has been rated as critical. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass.
This vulnerability is documented as CVE-2026-7502. The attack can be initiated remotely. Additionally, an exploit exists.
The pull request to fix this issue awaits acceptance.
A vulnerability was found in LinkStackOrg LinkStack up to 4.8.6. It has been declared as problematic. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting.
This vulnerability is registered as CVE-2026-7501. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project was informed of the problem early through a pull request but has not reacted yet.
A vulnerability was found in i18next i18next-http-middleware. It has been classified as critical. This issue affects some unknown processing. Performing a manipulation of the argument languages/namespaces results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-42353. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in CoreDNS 1.12.2/1.12.4/1.14.0/1.14.2 and classified as problematic. This vulnerability affects unknown code of the component DoQ Worker Pool. Such manipulation leads to allocation of resources.
This vulnerability is listed as CVE-2026-32934. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.