A vulnerability labeled as critical has been found in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-9752. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability described as problematic has been identified in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of the file /edit-profile.php of the component Edit Profile Page. Executing manipulation of the argument Username can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-9754. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability identified as problematic has been detected in Apache POI up to 5.2.0. Affected by this issue is some unknown functionality of the component HMEF. Performing manipulation results in allocation of resources.
This vulnerability is reported as CVE-2022-26336. The attacker must have access to the local network to execute the attack. No exploit exists.
You should upgrade the affected component.
A vulnerability classified as critical was found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.7. The impacted element is an unknown function of the component Web Runtime SEC. Executing manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2022-26336. The attack can only be executed locally. There is no exploit available.
A vulnerability was found in Oracle MySQL Connectors up to 8.0.27. It has been rated as critical. This vulnerability affects unknown code of the component Connector/J. The manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2022-21363. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in VMware Spring Security up to 5.6.8/5.7.4. This affects an unknown part. Performing manipulation results in improper authorization.
This vulnerability is reported as CVE-2022-31690. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in WP Private Content Plus Plugin up to 3.6.2 on WordPress. This impacts the function validate_restrictions. This manipulation causes information disclosure.
This vulnerability is registered as CVE-2025-4390. Remote exploitation of the attack is possible. No exploit is available.