A vulnerability categorized as problematic has been discovered in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting.
This vulnerability is known as CVE-2026-2224. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in code-projects Online Reviewer System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2026-2223. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in code-projects Online Reviewer System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting.
This vulnerability appears as CVE-2026-2222. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability was found in code-projects Online Reviewer System 1.0. It has been classified as critical. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injection.
This vulnerability is reported as CVE-2026-2221. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability was found in code-projects Online Reviewer System 1.0 and classified as critical. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation of the argument difficulty_id leads to sql injection.
This vulnerability is documented as CVE-2026-2220. The attack can be executed remotely. Additionally, an exploit exists.
A new open-source and cross-platform tool called Tirith can detect homoglyph attacks over command-line environments by analyzing URLs in typed commands and stopping their execution. [...]
A vulnerability has been found in D-Link DCS-933L up to 1.14.11 and classified as critical. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID causes command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is registered as CVE-2026-2218. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability, which was classified as critical, was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php. The manipulation of the argument ID results in sql injection.
This vulnerability is cataloged as CVE-2026-2217. The attack may be launched remotely. Furthermore, there is an exploit available.