A vulnerability identified as critical has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass.
This vulnerability is registered as CVE-2026-4549. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as critical has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection.
This vulnerability is documented as CVE-2026-4550. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability marked as critical has been reported in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the argument menufacturer/Go results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-4551. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability described as critical has been identified in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2026-4552. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability identified as critical has been detected in WWBN AVideo up to 25.x. This affects the function uploadVideoToLinkedIn of the component SocialMediaPublisher Plugin. This manipulation causes os command injection.
The identification of this vulnerability is CVE-2026-33319. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, was found in chuckmo Lobot Slider Administrator Plugin up to 0.6.0 on WordPress. The affected element is the function fourty_slider_options_page. Executing a manipulation can lead to cross-site request forgery.
This vulnerability is registered as CVE-2026-3331. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2026-4553. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection.
This vulnerability is known as CVE-2026-4554. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability, which was classified as critical, has been found in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2026-4555. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as problematic. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in cross site scripting.
This vulnerability was named CVE-2026-4557. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in Linksys MR9600 2.0.6.206937 and classified as critical. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection.
The identification of this vulnerability is CVE-2026-4558. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Alinto SOGo up to 5.12.4 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-71276. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in SPIP up to 4.4.12. It has been rated as problematic. This affects an unknown part of the component Data Structure Handler. This manipulation causes function call with incorrect variable or reference as argument.
This vulnerability is tracked as CVE-2026-33549. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, was found in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity.
This vulnerability is identified as CVE-2026-4539. The attack is only possible with local access. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability, which was classified as problematic, was found in Alinto SOGo up to 5.12.4. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to use of single-factor authentication.
This vulnerability is handled as CVE-2026-33550. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability identified as critical has been detected in Oracle Communications Pricing Design Center up to 12.0.0.7.0. This affects an unknown function of the component REST Service Manager. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2020-36518. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability marked as critical has been reported in Oracle Communications Policy Management 12.6.0.0.0. Affected by this vulnerability is an unknown functionality of the component Configuration Management Platform. This manipulation causes denial of service.
This vulnerability appears as CVE-2020-36518. The attack may be initiated remotely. There is no available exploit.
A vulnerability described as critical has been identified in Oracle Communications Services Gatekeeper 7.0.0.0.0. Affected by this issue is some unknown functionality of the component Core. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2020-36518. The attack may be launched remotely. There is no exploit available.