A vulnerability labeled as critical has been found in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2026-10259. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability identified as critical has been detected in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection.
This vulnerability is tracked as CVE-2026-10258. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability categorized as critical has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection.
This vulnerability is identified as CVE-2026-10257. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability was found in itsourcecode Content Management System 1.0. It has been rated as critical. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection.
This vulnerability is referenced as CVE-2026-10256. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability was found in OpenCATS up to 0.9.1a. It has been declared as critical. This affects an unknown part of the component DataGrid Filter. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2026-49490. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in OpenCATS up to 0.9.7.4. It has been classified as critical. Affected by this issue is the function ajax of the file ajax/getDataGridPager.php of the component DataGrid. Performing a manipulation of the argument sortDirection results in sql injection.
This vulnerability was named CVE-2026-49489. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0 and classified as problematic. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-10255. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0 and classified as problematic. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure.
This vulnerability is handled as CVE-2026-10254. The attack can be initiated remotely. Additionally, an exploit exists.
Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks.
The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices. More than 200 servers located in the Netherlands acted as the