💉 MingSoft MCMS SQL Injection Exposes Remote Attack Surface
Teams running MingSoft MCMS up to 3.0.6 should treat this as urgent because the exploit is already public. With no vendor response noted, restrict exposure and apply an effective mitigation or vendor remediation if one becomes available.
CVE-2026-19355 is a SQL injection vulnerability in MingSoft MCMS up to 3.0.6, affecting ModelDataImpl.queryDiyFormData in the ms-mdiy component through the formFields argument. The attack may be performed remotely, and the exploit has been publicly disclosed and may be utilized. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
💉 node-sql-query SQL Injection Fixed in 0.1.29
Applications using 0.1.25, 0.1.26, 0.1.27, or 0.1.28 should upgrade to 0.1.29 promptly. Public exploit availability makes this a priority for deployments that process untrusted request parameters.
CVE-2026-19351 is a SQL injection vulnerability in dresende node-sql-query versions 0.1.25, 0.1.26, 0.1.27, and 0.1.28, affecting SelectQuery.from and SelectQuery.build in lib/Select.js. The attack can be initiated remotely, and the exploit has been made public and could be used. It is rated HIGH with CVSS 7.3; upgrading to version 0.1.29 addresses the issue, with patch 3414c42f6de89826fa1f5f36f6139d1e6552778e.
🔗 Read more 🔗
Source: NVD
🚨 Aitemi M300 Command Injection Enables Remote Attacks
Owners and administrators of affected Aitemi M300 repeaters should prioritize mitigation immediately. Remote command injection combined with a public exploit and CRITICAL severity makes exposed devices especially risky.
CVE-2026-19348 is a command injection vulnerability in the Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a, involving the enable, name, and mac arguments handled by sprintf. The attack may be initiated remotely, and the exploit has been released to the public and may be used for attacks. It is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
⚠️ Tenda CH22 Command Injection Disclosed Publicly
Administrators running Tenda CH22 1.0.0.1 should isolate or otherwise mitigate affected devices as a high priority. Because the exploit is public, remotely reachable devices deserve immediate attention.
CVE-2026-19346 is a command injection vulnerability in Tenda CH22 1.0.0.1, affecting formCertListInfo in /goform/CertListInfo through manipulation of the Name argument. The attack can be initiated remotely, and the exploit has been publicly disclosed and may be utilized. It is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
💉 Task Management System Hit by SQL Injection
Anyone running code-projects Task Management System 1.0 should mitigate or restrict access quickly, especially when the application is reachable from untrusted networks. The public exploit raises the urgency for exposed deployments.
CVE-2026-19344 is a SQL injection vulnerability in code-projects Task Management System 1.0, affecting /user/comment_count_user.php through manipulation of the task_id argument. The attack can be initiated remotely, and the exploit has been disclosed to the public and may be used. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🔓 Task Management Admin Login Vulnerable to SQL Injection
Operators of code-projects Task Management System 1.0 should prioritize mitigation because the affected endpoint is the administrative login and the exploit is public. Restrict access until an effective fix or mitigation is in place.
CVE-2026-19343 is a SQL injection vulnerability in code-projects Task Management System 1.0 affecting /admin/AdminLogin.php through manipulation of the email and password arguments. The attack may be performed remotely, and the exploit has been published and may be used. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🔑 Task Management Login Flaw Enables Improper Authentication
Deployments of code-projects Task Management System 1.0 should be isolated or otherwise mitigated promptly because the flaw affects authentication itself. Public exploit availability makes exposed login pages a priority.
CVE-2026-19342 is an improper authentication vulnerability in the Login component of code-projects Task Management System 1.0, affecting /index.php through manipulation of the Password argument. The attack can be carried out remotely, and the exploit is now public and may be used. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD