A vulnerability was found in designcomputer mysql-mcp-server up to 0.2.2. It has been rated as critical. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection.
This vulnerability is registered as CVE-2026-11529. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2026-11528. The attack may be launched remotely. Furthermore, there is an exploit available.