A vulnerability marked as critical has been reported in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the file /hotel/admin/mod_users/index.php?view=edit&id=8 of the component Parameter Handler. The manipulation of the argument account_id leads to sql injection.
This vulnerability is referenced as CVE-2026-4612. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability labeled as critical has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection.
The identification of this vulnerability is CVE-2026-4611. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Tenda AC21 16.03.08.16. It has been rated as critical. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow.
This vulnerability is identified as CVE-2026-4565. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability categorized as critical has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formWISP5G of the file /goform/formWISP5G. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-4566. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability labeled as critical has been found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /update_supplier.php of the component HTTP GET Request Handler. The manipulation of the argument sid results in sql injection.
This vulnerability is cataloged as CVE-2026-4568. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability marked as critical has been reported in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of the component HTTP POST Request Handler. This manipulation of the argument searchtxt causes sql injection.
This vulnerability is registered as CVE-2026-4569. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability identified as critical has been detected in GeoVision GV-Edge Recording Manager up to 2.3.1. Affected by this vulnerability is an unknown functionality of the component Windows Service. Performing a manipulation results in execution with unnecessary privileges.
This vulnerability was named CVE-2026-4606. The attack needs to be approached locally. There is no available exploit.
You should upgrade the affected component.
A vulnerability identified as critical has been detected in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2026-4567. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability described as critical has been identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manipulation of the argument searchtxt leads to sql injection.
This vulnerability is documented as CVE-2026-4570. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability classified as critical has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_payments.php of the component HTTP POST Request Handler. Performing a manipulation of the argument searchtxt results in sql injection.
This vulnerability is reported as CVE-2026-4571. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability identified as critical has been detected in GeoVision GV-Edge Recording Manager up to 2.3.1. Affected by this vulnerability is an unknown functionality of the component Windows Service. Performing a manipulation results in execution with unnecessary privileges.
This vulnerability was named CVE-2026-4606. The attack needs to be approached locally. There is no available exploit.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in flippercode WP Maps Plugin up to 4.9.1 on WordPress. Affected is an unknown function of the component Parameter Handler. Such manipulation of the argument orderby leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-2580. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in ReviewX Plugin up to 2.2.10 on WordPress. It has been rated as critical. This impacts the function userAccessibility of the component REST API Endpoint. This manipulation causes improper authorization.
This vulnerability is handled as CVE-2025-10736. The attack can be initiated remotely. There is not any exploit available.