A vulnerability, which was classified as critical, was found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_460F30 of the file /boafrm/formDateReboot of the component Scheduled Reboot Configuration Endpoint. The manipulation of the argument submit-url results in stack-based buffer overflow.
This vulnerability was named CVE-2026-2962. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability, which was classified as critical, has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4196C4 of the file /boafrm/formVpnConfigSetup of the component VPN Configuration Endpoint. The manipulation of the argument submit-url leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-2961. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability classified as critical was found in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_468D64 of the file /boafrm/formDhcpv6s. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow.
This vulnerability is handled as CVE-2026-2960. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability classified as critical has been found in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_44E0F8 of the file /boafrm/formNewSchedule. Performing a manipulation of the argument url results in stack-based buffer overflow.
This vulnerability is known as CVE-2026-2959. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability described as critical has been identified in D-Link DWR-M960 1.01.07. Affected is the function sub_457C5C of the file /boafrm/formWsc. Such manipulation of the argument save_apply leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2026-2958. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability marked as problematic has been reported in qinming99 dst-admin up to 1.5.0. This impacts the function deleteBackup of the file src/main/java/com/tugos/dst/admin/controller/BackupController.java of the component File Handler. This manipulation causes denial of service.
This vulnerability appears as CVE-2026-2957. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability labeled as critical has been found in qinming99 dst-admin up to 1.5.0. This affects the function revertBackup of the file /home/restore. The manipulation of the argument Name results in command injection.
This vulnerability is reported as CVE-2026-2956. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability identified as problematic has been detected in Conditional CAPTCHA Plugin up to 4.0.0 on WordPress. The impacted element is an unknown function. The manipulation leads to open redirect.
This vulnerability is documented as CVE-2026-1369. The attack can be initiated remotely. There is not any exploit available.
A vulnerability identified as critical has been detected in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to missing authorization.
This vulnerability is listed as CVE-2026-2819. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.