A vulnerability classified as critical was found in Microchip Time Provider 4100 up to 2.4.x. The affected element is an unknown function of the component Software Update Handler. Such manipulation leads to hard-coded credentials.
This vulnerability is traded as CVE-2025-9497. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in wpquads Quads Ads Manager for Google AdSense Plugin up to 2.0.98.1 on WordPress. Impacted is an unknown function of the component Parameter Handler. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-2595. The attack may be initiated remotely. There is no available exploit.
A vulnerability described as problematic has been identified in softaculous Page Builder Plugin up to 2.0.7 on WordPress. This issue affects some unknown processing. The manipulation results in crlf injection.
This vulnerability is reported as CVE-2026-2442. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as critical, was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the component NTP Service. The manipulation results in os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is cataloged as CVE-2026-4627. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in itsourcecode Online Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /sms/user/index.php?view=add of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection.
This vulnerability appears as CVE-2026-4632. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability, which was classified as critical, was found in woobewoo Product Filter for WooCommerce by WBW Plugin up to 3.1.2 on WordPress. This affects an unknown part of the component AJAX Handler. The manipulation results in missing authorization.
This vulnerability is reported as CVE-2026-3138. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability has been found in legalweb WP DSGVO Tools Plugin up to 3.1.38 on WordPress and classified as critical. This vulnerability affects unknown code of the component Shortcode Handler. This manipulation of the argument username/email causes missing authorization.
This vulnerability appears as CVE-2026-4283. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability was found in Undertow. It has been rated as problematic. The impacted element is the function getParameterMap. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2026-3260. The attack is possible to be carried out remotely. No exploit exists.