7.5

CVSS3.0

CVE-2026-0558 - Unauthenticated File Upload in parisneo/lollms

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the `Depends(get_current_acti…

📅 Published: March 29, 2026, 5:53 p.m. 🔄 Last Modified: March 29, 2026, 5:53 p.m.

7.5

CVSS3.0

CVE-2026-0560 - Server-Side Request Forgery (SSRF) in parisneo/lollms

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails to validate user-controlled URLs, allowing attackers to make a…

📅 Published: March 29, 2026, 5:51 p.m. 🔄 Last Modified: March 29, 2026, 5:51 p.m.

8.3

CVSS3.0

CVE-2026-0562 - Insecure Direct Object Reference (IDOR) in parisneo/lollms

A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not implement proper authorization checks, enabling Insecure Di…

📅 Published: March 29, 2026, 5:49 p.m. 🔄 Last Modified: March 29, 2026, 5:49 p.m.

8.8

CVSS3.1

CVE-2026-34005 -

In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.

📅 Published: March 29, 2026, 5:02 p.m. 🔄 Last Modified: March 29, 2026, 5:02 p.m.

8.7

CVSS4.0

CVE-2026-5046 - Tenda FH1201 Parameter WrlExtraSet formWrlExtraSet stack-based overflow

A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component Parameter Handler. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit…

📅 Published: March 29, 2026, 2:15 p.m. 🔄 Last Modified: March 29, 2026, 2:15 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here