A vulnerability marked as critical has been reported in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection.
This vulnerability is referenced as CVE-2026-8259. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability labeled as critical has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow.
The identification of this vulnerability is CVE-2026-8258. The attack can only be executed locally. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability identified as problematic has been detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion.
This vulnerability was named CVE-2026-8257. The attack needs to be approached locally. In addition, an exploit is available.
It is suggested to install a patch to address this issue.
A vulnerability categorized as problematic has been discovered in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown code of the file /accounts/mr-save. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-8256. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Devs Palace ERP Online up to 4.0.0. It has been rated as problematic. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-8255. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Devs Palace ERP Online up to 4.0.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-8254. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Devs Palace ERP Online up to 4.0.0. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-8253. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Open5GS up to 2.7.7 and classified as problematic. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference.
This vulnerability appears as CVE-2026-8252. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability has been found in Open5GS up to 2.7.7 and classified as problematic. This impacts the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. Performing a manipulation results in denial of service.
This vulnerability is reported as CVE-2026-8251. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability, which was classified as problematic, was found in Open5GS up to 2.7.7. This affects the function smf_n4_build_qos_flow_to_modify_list of the file /src/smf/n4-build.c of the component SMF. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-8250. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.7. The impacted element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. This manipulation causes denial of service.
This vulnerability is registered as CVE-2026-8249. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.