5.1

CVSS4.0

CVE-2026-5679 - Totolink A3300R cstecgi.cgi vsetTr069Cfg os command injection

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. The exploit has been disclosed publicly and may be used.

πŸ“… Published: April 6, 2026, 7 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

7.1

CVSS3.1

CVE-2026-35176 - openFPGALoader has a heap buffer overflow in POFParser::parseSection() via crafted .pof file

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in POFParser::parseSection() that allows out-of-bounds heap memory access when parsing a crafted .pof file. No FPGA hardware is required to trigger this vulnerability.

πŸ“… Published: April 6, 2026, 6:59 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

9.3

CVSS4.0

CVE-2026-35022 - Anthropic Claude Code & Agent SDK OS Command Injection via Authentication Helper

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are executed using shell=true without input validation. Attackers who can influence authentication settings can inject shell metacharacte…

πŸ“… Published: April 6, 2026, 6:59 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

8.4

CVSS4.0

CVE-2026-35021 - Anthropic Claude Code & Agent SDK OS Command Injection via promptEditor.ts

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions in…

πŸ“… Published: April 6, 2026, 6:59 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

7.1

CVSS3.1

CVE-2026-35170 - openFPGALoader has a heap buffer overflow in BitParser::parseHeader() via crafted .bit file

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in BitParser::parseHeader() that allows out-of-bounds heap memory access when parsing a crafted .bit file. No FPGA hardware is required to trigger this vulnerability.

πŸ“… Published: April 6, 2026, 6:59 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

8.6

CVSS4.0

CVE-2026-35020 - Anthropic Claude Code & Agent SDK OS Command Injection via TERMINAL Environment Variable

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows local attackers to execute arbitrary commands by manipulating the TERMINAL environment variable. Attackers can inject shell metachara…

πŸ“… Published: April 6, 2026, 6:58 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

6.9

CVSS4.0

CVE-2026-5678 - Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. The exploit has been ma…

πŸ“… Published: April 6, 2026, 6:45 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

6.9

CVSS4.0

CVE-2026-5677 - Totolink A7100RU cstecgi.cgi CsteSystem os command injection

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection. The attack may be initiated remotely. The exploit has been releas…

πŸ“… Published: April 6, 2026, 6:30 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

6.2

CVSS3.1

CVE-2026-0049 - Persistent Denial of Service via Resource Exhaustion in LocalImageResolver

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: April 6, 2026, 6:20 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

0.0

CVE-2025-48651 -

StrongBox in Android before security patch level 2026-04-05 has a vulnerability of High Severity, aka A-434039170, A-467765081, A-467765894, and A-467762899.

πŸ“… Published: April 6, 2026, 6:20 p.m. πŸ”„ Last Modified: April 6, 2026, 8:16 p.m.
Total resulsts: 342654
Page 10 of 34,266
Β« previous page Β» next page
Filters