A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20 and classified as problematic. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The manipulation of the argument ID results in improper control of resource identifiers.
This vulnerability is reported as CVE-2026-5031. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection.
This vulnerability is documented as CVE-2026-5030. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability, which was classified as critical, was found in CodeRider-Kilo. This vulnerability affects unknown code of the component Parser. Executing a manipulation can lead to os command injection.
This vulnerability is registered as CVE-2026-30302. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as critical, has been found in Wazuh up to 4.7.3/4.7.x. This affects an unknown part of the component authd. Performing a manipulation results in incorrect default permissions.
This vulnerability is cataloged as CVE-2026-32983. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_category of the file Actions.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection.
This vulnerability is listed as CVE-2026-30531. The attack may be performed from remote. There is no available exploit.
A vulnerability classified as problematic has been found in langflow-ai langflow. Affected by this vulnerability is an unknown functionality of the file /api/v1/files/images/ of the component SVG File Handler. This manipulation of the argument flow_id causes cross site scripting.
This vulnerability is tracked as CVE-2026-5026. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability described as problematic has been identified in Inkscape up to 1.2. Affected is an unknown function of the component XInclude Handler. The manipulation results in xml external entity reference.
This vulnerability is identified as CVE-2026-4980. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in Wazuh 3.5.0/4.3.10. This impacts an unknown function of the component authd. The manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-32984. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as critical has been found in langflow-ai langflow. This affects an unknown function of the file /api/v2/files of the component Multipart Form Data Parser. Executing a manipulation of the argument filename can lead to path traversal.
The identification of this vulnerability is CVE-2026-5027. The attack may be launched remotely. There is no exploit available.
A vulnerability identified as problematic has been detected in langflow-ai langflow. The impacted element is the function get_current_active_user of the file /logs of the component Endpoint. Performing a manipulation results in missing authorization.
This vulnerability was named CVE-2026-5025. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as critical has been discovered in SourceCodester Food Ordering System 1.0. The affected element is an unknown function of the file admin/manage_category.php of the component Parameter Handler. Such manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-30534. The attack can be launched remotely. No exploit exists.