Navia Benefit Solutions, Inc. (Navia) is informing nearly 2.7 million individuals of a data breach that exposed their sensitive information to attackers. [...]
A vulnerability classified as problematic has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php. This manipulation of the argument st_name causes cross site scripting.
This vulnerability appears as CVE-2026-4474. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability described as critical has been identified in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appointment_action.php. The manipulation of the argument appointment_id results in sql injection.
This vulnerability is reported as CVE-2026-4473. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability marked as critical has been reported in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /admin/admin_edit_supplier.php. The manipulation of the argument Supplier_Name leads to sql injection.
This vulnerability is documented as CVE-2026-4472. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability labeled as critical has been found in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_employee.php. Executing a manipulation of the argument First_Name can lead to sql injection.
This vulnerability is registered as CVE-2026-4471. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability identified as critical has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_edit_menu.php. Performing a manipulation of the argument product_name results in sql injection.
This vulnerability is cataloged as CVE-2026-4470. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability categorized as critical has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_edit_menu_action.php. Such manipulation of the argument product_name leads to sql injection.
This vulnerability is listed as CVE-2026-4469. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability was found in Comfast CF-AC100 2.6.0.8. It has been rated as critical. Affected is an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=update_interface_png. This manipulation causes command injection.
This vulnerability is tracked as CVE-2026-4468. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Comfast CF-AC100 2.6.0.8. It has been declared as critical. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=wireless_device_dissoc. The manipulation results in command injection.
This vulnerability is identified as CVE-2026-4467. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Comfast CF-AC100 2.6.0.8. It has been classified as critical. This affects an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone. The manipulation leads to command injection.
This vulnerability is referenced as CVE-2026-4466. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.