- CVE-2026-100896 HIGH CVSS 8.6 -
NVD: A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. NVD: The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. NVD: This manipulation of the argument wlanif causes os command injection.
An attacker may be able to run unintended system commands through the affected component; CVSS 8.6 (HIGH); EPSS percentile 79; sources: NVD.
- CVE-2026-100902 MEDIUM CVSS 5.7 -
NVD: A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. NVD: Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. NVD: This manipulation of the argument wallpaper causes improper validation of syntactic correctness of input.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.7 (MEDIUM); EPSS percentile 25; sources: NVD.
- CVE-2026-100895 MEDIUM CVSS 5.5 -
NVD: A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. NVD: Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. NVD: The manipulation results in null pointer dereference.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 50; sources: NVD, OSV.
- CVE-2026-100892 MEDIUM CVSS 5.5 -
NVD: A vulnerability was found in aligungr UERANSIM up to 3.3.0. NVD: This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. NVD: Performing a manipulation of the argument dedicatedNASMessage results in memory corruption.
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 5.5 (MEDIUM); EPSS percentile 47; sources: NVD.
- CVE-2026-100903 MEDIUM CVSS 5.5 -
NVD: A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. NVD: This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. NVD: Such manipulation of the argument objectId leads to missing authentication.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 37; sources: NVD.
- CVE-2026-100893 MEDIUM CVSS 5.5 -
NVD: A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. NVD: This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. NVD: Executing a manipulation of the argument url can lead to server-side request forgery.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 37; sources: NVD.
- CVE-2026-100890 MEDIUM CVSS 5.5 -
NVD: A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. NVD: Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. NVD: This manipulation of the argument cp causes null pointer dereference.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 29; sources: NVD.
- CVE-2026-100889 MEDIUM CVSS 5.5 -
NVD: A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. NVD: Affected is the function dkim_qp_decode of the file util.c of the component Decoder. NVD: The manipulation results in off-by-one.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 21; sources: NVD.
- CVE-2026-100888 MEDIUM CVSS 5.5 -
NVD: A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. NVD: This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. NVD: Executing a manipulation of the argument h can lead to out-of-bounds write.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 20; sources: NVD.
- CVE-2026-100891 MEDIUM CVSS 5.5 -
NVD: A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. NVD: Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. NVD: Such manipulation leads to encoding error.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 20; sources: NVD.
- CVE-2026-100906 MEDIUM CVSS 5.5 -
NVD: A vulnerability was detected in Eyeplus 57.0.0.0308. NVD: The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. NVD: The manipulation results in information disclosure.
An attacker may be able to access information that should not be exposed; CVSS 5.5 (MEDIUM); EPSS percentile 19; sources: NVD.
- CVE-2026-100907 MEDIUM CVSS 5.5 -
NVD: A flaw has been found in Eyeplus 57.0.0.0308. NVD: The impacted element is an unknown function of the file /snapshot of the component p2pcam Service. NVD: This manipulation causes information disclosure.
An attacker may be able to access information that should not be exposed; CVSS 5.5 (MEDIUM); EPSS percentile 19; sources: NVD.
- CVE-2026-100901 MEDIUM CVSS 5.5 -
NVD: A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. NVD: Affected by this vulnerability is the function stream of the file public/stream.php. NVD: The manipulation of the argument url results in server-side request forgery.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 18; sources: NVD.
- CVE-2026-100904 MEDIUM CVSS 5.1 -
NVD: A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. NVD: Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. NVD: The manipulation of the argument itemName leads to cross site scripting.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 5.1 (MEDIUM); EPSS percentile 8; sources: NVD.
- CVE-2026-100897 MEDIUM CVSS 5.1 -
NVD: A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. NVD: The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the component Password Change Endpoint. NVD: Such manipulation of the argument sid/tid leads to authorization bypass.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.1 (MEDIUM); EPSS percentile 5; sources: NVD.
- CVE-2026-100894 LOW CVSS 2.1 -
NVD: A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: This issue affects some unknown processing of the file updateguest.php. NVD: The manipulation of the argument gname leads to sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 21; sources: NVD.
- CVE-2026-100887 LOW CVSS 2.1 -
NVD: A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. NVD: The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. NVD: Performing a manipulation of the argument orderBy results in sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 8; sources: NVD.
- CVE-2026-100898 LOW CVSS 2.1 -
NVD: A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. NVD: This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. NVD: Performing a manipulation of the argument filter results in sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 8; sources: NVD.
- CVE-2026-100899 LOW CVSS 2.1 -
NVD: A flaw has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. NVD: This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. NVD: Executing a manipulation of the argument filter can lead to sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 8; sources: NVD.
- CVE-2026-100900 LOW CVSS 2.0 -
NVD: A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. NVD: Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. NVD: The manipulation of the argument host/username/token leads to server-side request forgery.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.0 (LOW); EPSS percentile 4; sources: NVD.