9.3

CVSS4.0

CVE-2026-7155 - Totolink A8000RU CGI cstecgi.cgi setLoginPasswordCfg os command injection

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass leads to os command injection. The attack may be initiated remote…

πŸ“… Published: April 27, 2026, 8:15 p.m. πŸ”„ Last Modified: April 28, 2026, 8:24 p.m.

8.6

CVSS4.0

CVE-2026-7191 - Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS

Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content …

πŸ“… Published: April 27, 2026, 8:08 p.m. πŸ”„ Last Modified: April 28, 2026, 2:36 p.m.

9.3

CVSS4.0

CVE-2026-7154 - Totolink A8000RU CGI cstecgi.cgi setAdvancedInfoShow os command injection

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument tty_server can lead to os command injection. The attack can be launched remot…

πŸ“… Published: April 27, 2026, 8 p.m. πŸ”„ Last Modified: April 28, 2026, 2:36 p.m.

9.3

CVSS4.0

CVE-2026-7153 - Totolink A8000RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sys_info results in os command injection. The attack can b…

πŸ“… Published: April 27, 2026, 7:45 p.m. πŸ”„ Last Modified: April 28, 2026, 12:49 p.m.

8.8

CVSS3.1

CVE-2026-6741 - LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-cust…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of the connect-customer-to-wp-user ability, which only requires …

πŸ“… Published: April 27, 2026, 7:36 p.m. πŸ”„ Last Modified: April 28, 2026, 2:49 p.m.

9.3

CVSS4.0

CVE-2026-7152 - Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument telnet_enabled leads to os command injection. It is possible to launch the attac…

πŸ“… Published: April 27, 2026, 7:30 p.m. πŸ”„ Last Modified: April 28, 2026, 3:37 p.m.

8.7

CVSS4.0

CVE-2026-7151 - Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow

A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and …

πŸ“… Published: April 27, 2026, 7:15 p.m. πŸ”„ Last Modified: April 30, 2026, 6:22 p.m.

7

CVSS4.0

CVE-2026-5394 - Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.

πŸ“… Published: April 27, 2026, 7:15 p.m. πŸ”„ Last Modified: April 28, 2026, 2:36 p.m.

5

CVSS3.1

CVE-2026-40970 - Spring Boot: Spring Boot: Missing hostname verification in Elasticsearch auto-configuration allows …

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

πŸ“… Published: April 27, 2026, 7:09 p.m. πŸ”„ Last Modified: April 28, 2026, 7:45 p.m.

5.3

CVSS4.0

CVE-2026-7150 - dh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forgery

A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. The manipulation of the argument image_url results in server-side request forg…

πŸ“… Published: April 27, 2026, 7 p.m. πŸ”„ Last Modified: April 28, 2026, 2:19 p.m.
Total resulsts: 347818
Page 102 of 34,782
Β« previous page Β» next page
Filters