The list of countries exploiting Internet-connected cameras to give them eyes inside their adversaries' borders continues to expand. What should companies look out for?
A vulnerability classified as critical has been found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the component Endpoint. Performing a manipulation of the argument page results in stack-based buffer overflow.
This vulnerability is identified as CVE-2026-5036. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability described as critical has been identified in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en_id leads to sql injection.
This vulnerability is referenced as CVE-2026-5035. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability marked as critical has been reported in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection.
The identification of this vulnerability is CVE-2026-5034. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability labeled as critical has been found in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The manipulation of the argument cos_id results in sql injection.
This vulnerability was named CVE-2026-5033. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability identified as problematic has been detected in Wazuh 3.5.0/4.3.10. Affected is an unknown function of the component authd. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2023-7340. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in SourceCodester Online Food Ordering System 1.0. This impacts the function save_customer of the file Actions.php of the component Parameter Handler. Executing a manipulation of the argument Username can lead to sql injection.
This vulnerability is handled as CVE-2026-30530. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in SourceCodester Online Food Ordering System 1.0. It has been rated as problematic. This affects an unknown function of the component Category Management Module. Performing a manipulation of the argument Category Name results in cross site scripting.
This vulnerability is known as CVE-2026-30527. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in SourceCodester Food Ordering System 1.0. It has been declared as critical. The impacted element is an unknown function of the file Actions.php of the component Parameter Handler. Such manipulation of the argument Username leads to sql injection.
This vulnerability is traded as CVE-2026-30529. The attack may be launched remotely. There is no exploit available.