🔓 VULNERABILITIES & CVEs
-
CVE-2026-16331 — D-Link DNS-320 save_ajax.php unrestricted upload — CVSS 7.3 A security vulnerability has been identified in the save_ajax.php component of the D-Link DNS-320, allowing unrestricted file uploads.
- This flaw can enable attackers to upload malicious files, potentially leading to remote code execution or device compromise.
-
CVE-2026-16330 — D-Link DNS-320 uploadify.php unrestricted upload — CVSS 7.3 A weakness has been identified in the uploadify.php script of the D-Link DNS-320 that permits unrestricted file uploads.
- Exploiting this vulnerability could allow unauthorized users to upload arbitrary files.
-
CVE-2026-16329 — D-Link DNS-320 uploadify.php unrestricted upload — CVSS 7.3 A vulnerability was identified in the uploadify.php of D-Link DNS-320 enabling unrestricted file uploads.
- This issue poses a risk of remote code execution or other malicious activity.
-
CVE-2026-16332 — D-Link DNS-320 multi_uploadify.php unrestricted upload A vulnerability was detected in the multi_uploadify.php component of D-Link DNS-320 allowing unrestricted file uploads.
- Attackers could exploit this to upload harmful files without authentication.
-
CVE-2026-16334 — itsourcecode Hospital Management System prescriptionorder.php SQL injection A SQL injection vulnerability exists in the prescriptionorder.php of itsourcecode Hospital Management System.
- This flaw could allow attackers to manipulate database queries and access sensitive data.
-
CVE-2026-6952 — Post-authentication command injection in LogServer A post-authentication command injection vulnerability exists in the "LogServer" file handling.
- Exploiting this could lead to remote command execution on affected systems.
-
CVE-2026-63729 — TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File The SyncTeX parser in TeX Live is vulnerable to a heap use-after-free triggered by malformed SyncTeX files.
- This vulnerability may cause crashes or potentially allow code execution.