|
1721
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manip…
|
CWE-22
Path Traversal
|
CVE-2026-9473
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1722
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipu…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9475
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1723
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interfa…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9476
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1724
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file /student.php. Performing a manipulation…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9471
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1725
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src…
|
CWE-22
Path Traversal
|
CVE-2026-9472
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1726
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the function confirm_logged_in of the file /studentdel.…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9474
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1727
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interf…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9477
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1728
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9478
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1729
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deseriali…
|
CWE-20 CWE-502
Improper Input Validation Deserialization of Untrusted Data
|
CVE-2026-9497
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1730
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument De…
|
CWE-791 CWE-1336
Incomplete Filtering of Special Elements Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-9498
|
2026-05-27 04:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|