A vulnerability was found in CodeAstro Ingredients Stock Management System 1.0 and classified as critical. This impacts an unknown function of the file /Ingredients-Stock/add_stock.php. The manipulation of the argument ID results in sql injection.
This vulnerability is cataloged as CVE-2026-11495. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.8611 and classified as critical. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation.
This vulnerability is listed as CVE-2026-11494. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements.
This vulnerability is tracked as CVE-2026-11493. The attack is only possible within the local network. Moreover, an exploit is present.
A vulnerability, which was classified as critical, has been found in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation.
This vulnerability is identified as CVE-2026-11492. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability classified as problematic was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Triggered by Ashik Mohamed')"> as part of POST leads to cross site scripting.
This vulnerability is referenced as CVE-2026-11491. It is possible to launch the attack remotely. Furthermore, an exploit is available.