Feed/CVE-2026-2196
CVE-2026-2196HIGHCVSS 7.3

CVE-2026-2196

Published Feb 8, 2026·Updated Jun 17, 2026

NVD Description

A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

Public Exploits & PoCs7 found

[POC] CVE-2026-21962 — CVE-2026-21962-Oracle-HTTP-Server-WebLogic-Proxy-Plug-in-Critical-

Oracle Fusion Middleware Oracle HTTP Server / WebLogic Server Proxy Plug-in has an easily exploitable, unauthenticated, network-reachable flaw allowing compromise over HTTP. Affected supported versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0.

1

[POC] CVE-2026-21962 — CVE-2026-21962

Unauthenticated vulnerability that may allow remote attackers to compromise confidentiality and integrity, potentially leading to full system compromise.

1

[POC] CVE-2026-21962 — Ashwesker-CVE-2026-21962

CVE-2026-21962

1

[POC] CVE-2026-21962 — Ashwesker-CVE-2026-21962

CVE-2026-21962

[POC] CVE-2026-21962 — CVE-2026-21962

CVE-2026-21962-EXP

[POC] CVE-2026-21962 — CVE-2026-21962

CVE Finder

[POC] CVE-2026-21962 — CVE-2026-21962

CVE-2026-21962

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free