🚨 Critical TOTOLINK NR1800X Buffer Overflow Exposes Remote Attack Surface
Operators running the affected TOTOLINK firmware should treat this as an emergency patch or mitigation priority because exploitation is remote and exploit code is already public.
CVE-2026-82616 is a stack-based buffer overflow in TOTOLINK NR1800X 9.1.0u.6681_B20230703, affecting the setUploadSetting function in /cgi-bin/cstecgi.cgi through manipulation of the FileName argument. The vulnerability can be exploited remotely, and a public exploit is available. It is rated CRITICAL with CVSS 9.9.
🔗 Read more 🔗
Source: NVD
💉 Medicine Delivery Password Recovery Hit by SQL Injection
Anyone hosting this application should patch or restrict access promptly, especially because a public exploit may make opportunistic attacks easier.
CVE-2026-82615 is an SQL injection vulnerability in itsourcecode Online Medicine Delivery System 1.0, affecting Customer::find_phone in /passwordrecover.php. Attackers can manipulate the phonenumber argument remotely, and the exploit has been publicly disclosed. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
💉 Product Category Filter in Medicine Delivery App Vulnerable to SQL Injection
Internet-facing deployments should be patched or isolated quickly because the vulnerable parameter is remotely reachable and exploit details are already public.
CVE-2026-82614 affects itsourcecode Online Medicine Delivery System 1.0 and introduces SQL injection through the Category argument handled by loadResultList in /index.php?q=product. The flaw is remotely exploitable, and an exploit has been published. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🔐 AshPhoenix Tenant Authorization Bug Can Bypass Scoped Access Checks
Teams using tenant-scoped authorization with affected ash_phoenix releases should upgrade to 2.3.25 or later promptly, particularly where LiveView subdomain hooks protect sensitive multi-tenant data.
CVE-2026-82724 is an incorrect authorization vulnerability in ash-project ash_phoenix from 2.1.26 before 2.3.25. AshPhoenix.LiveView.SubdomainHook can invoke an authorization callback with a nil tenant before the real tenant is assigned, potentially causing tenant-scoped checks to crash or take a permissive path. It is rated HIGH with CVSS 7.6.
🔗 Read more 🔗
Source: NVD
💉 Medicine Delivery Product Detail Page Exposes SQL Injection
Patch or remove exposed instances quickly because the vulnerable endpoint is remotely accessible and public exploit information is available.
CVE-2026-82612 is an SQL injection flaw in itsourcecode Online Medicine Delivery System 1.0, affecting loadResultList in /index.php?q=single-item. Manipulation of the ID argument can trigger the vulnerability remotely, and the exploit has been publicly disclosed. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🔓 Customer Login in Medicine Delivery System Vulnerable to SQL Injection
Administrators of affected deployments should patch urgently and review exposed login endpoints, as public exploit availability increases the risk of attempted attacks.
CVE-2026-82611 affects itsourcecode Online Medicine Delivery System 1.0 and is an SQL injection vulnerability in Customer::cusAuthentication within /login.php. Remote attackers can manipulate the U_USERNAME argument, and exploit material is publicly available. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🔓 Rider Login SQL Injection Threatens Medicine Delivery System
Patch affected systems promptly and consider restricting the rider login interface until remediated because remote exploitation details are already public.
CVE-2026-82610 is an SQL injection vulnerability in itsourcecode Online Medicine Delivery System 1.0, affecting Employee::employeeAuthentication in /rider/login.php. The emp_email argument can be manipulated remotely, and the exploit has been released to the public. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
💥 AshAdmin Atom Exhaustion Can Crash Entire BEAM Nodes
Any reachable AshAdmin deployment should upgrade to 1.3.1 or later quickly, since an attacker able to access the admin LiveView could potentially cause a full application-node denial of service.
CVE-2026-82722 is a resource exhaustion vulnerability in ash-project ash_admin from 0.1.0 before 1.3.1. Client-controlled values passed to Module.concat/1 and String.to_atom/1 can create unlimited atoms, eventually exhausting the fixed BEAM atom table and crashing the entire node. It is rated HIGH with CVSS 8.3.
🔗 Read more 🔗
Source: NVD
📁 AshAdmin Path Traversal Enables Arbitrary Server File Writes
Upgrade affected AshAdmin installations to 1.3.1 or later as a high priority, especially where file uploads are exposed, because arbitrary file write can become a route to full server compromise.
CVE-2026-82673 is a path traversal vulnerability in ash-project ash_admin from 0.13.7 before 1.3.1. Unsanitized browser-supplied upload filenames can escape the temporary upload directory and write attacker-controlled bytes anywhere the BEAM process has permission to write, potentially enabling remote code execution. It is rated HIGH with CVSS 8.3.
🔗 Read more 🔗
Source: NVD
📡 Kamailio AVP Handler Flaw Allows Remote Out-of-Bounds Read
Kamailio operators should apply the available fix promptly; deployments on the obsolete 5.5.0 branch should also move to a maintained release rather than relying on an unsupported version.
CVE-2026-82608 is an out-of-bounds read vulnerability affecting Kamailio up to 5.5.0/6.0.7 in the get_4bytes function of src/modules/ims_registrar_scscf/cxdx_avp.c. The issue can be triggered remotely, a public exploit has been disclosed, and patch abb5d60af6eefbd367bf6588c5589566b090e272 addresses it. It is rated HIGH with CVSS 7.4.
🔗 Read more 🔗
Source: NVD
🔎 Medicine Delivery Product Search Exposed to SQL Injection
Patch public-facing installations promptly and monitor the affected search endpoint, as published exploit information lowers the barrier for attempted exploitation.
CVE-2026-82613 is an SQL injection vulnerability in itsourcecode Online Medicine Delivery System 1.0, affecting loadResultList in the Product Search Interface at /index.php?q=product. Manipulation of the Search argument can be performed remotely, and the exploit is public. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🧨 Stored XSS in AshAdmin Can Execute Code in Administrator Sessions
Upgrade AshAdmin to 1.3.1 or later promptly, particularly when lower-privileged users can create or edit records later displayed to administrators, since exploitation can inherit the administrator’s application privileges.
CVE-2026-77850 is a stored cross-site scripting vulnerability in ash-project ash_admin from 0.13.0 before 1.3.1. Relationship typeahead components render database-backed labels through Phoenix.HTML.raw/1, allowing malicious stored content to execute JavaScript when an administrator views matching records. It is rated HIGH with CVSS 8.4.
🔗 Read more 🔗
Source: NVD