5.3

CVSS4.0

CVE-2026-6119 - AstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery

A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used.…

πŸ“… Published: April 12, 2026, 5 a.m. πŸ”„ Last Modified: April 14, 2026, 4:33 p.m.

5.3

CVSS4.0

CVE-2026-6118 - AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection

A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. This manipulation of the argument command causes command injection. The attack is possible to be carried out remot…

πŸ“… Published: April 12, 2026, 4:45 a.m. πŸ”„ Last Modified: April 14, 2026, 1:56 p.m.

5.3

CVSS4.0

CVE-2026-6117 - AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload Endpoint. The manipulation of the argument File results in sandbox issue. The attack can be executed re…

πŸ“… Published: April 12, 2026, 4:30 a.m. πŸ”„ Last Modified: April 15, 2026, 3:18 p.m.

9.3

CVSS4.0

CVE-2026-6116 - Totolink A7100RU CGI cstecgi.cgi setDiagnosisCfg os command injection

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument ip leads to os command injection. Remote exploitation of the attack is pos…

πŸ“… Published: April 12, 2026, 4:15 a.m. πŸ”„ Last Modified: April 12, 2026, 5:16 a.m.

9.3

CVSS4.0

CVE-2026-6115 - Totolink A7100RU CGI cstecgi.cgi setAppCfg os command injection

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead to os command injection. The attack may be launched remotely. The exploit has b…

πŸ“… Published: April 12, 2026, 4 a.m. πŸ”„ Last Modified: April 13, 2026, 5:50 p.m.

9.3

CVSS4.0

CVE-2026-6114 - Totolink A7100RU CGI cstecgi.cgi setNetworkCfg os command injection

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument proto results in os command injection. The attack may be initiated rem…

πŸ“… Published: April 12, 2026, 3:30 a.m. πŸ”„ Last Modified: April 14, 2026, 4:33 p.m.

9.3

CVSS4.0

CVE-2026-6113 - Totolink A7100RU CGI cstecgi.cgi setTtyServiceCfg os command injection

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument ttyEnable leads to os command injection. The attack c…

πŸ“… Published: April 12, 2026, 3 a.m. πŸ”„ Last Modified: April 14, 2026, 1:58 p.m.

9.3

CVSS4.0

CVE-2026-6112 - Totolink A7100RU CGI cstecgi.cgi setRadvdCfg os command injection

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exp…

πŸ“… Published: April 12, 2026, 2:45 a.m. πŸ”„ Last Modified: April 15, 2026, 3:17 p.m.

5.3

CVSS4.0

CVE-2026-6111 - FoundationAgents MetaGPT common.py decode_image server-side request forgery

A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit …

πŸ“… Published: April 12, 2026, 2:30 a.m. πŸ”„ Last Modified: April 12, 2026, 3:16 a.m.

8.2

CVSS3.0

CVE-2026-1116 - Cross-site Scripting (XSS) in parisneo/lollms

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `content` field when deserializing user-provided data. This a…

πŸ“… Published: April 12, 2026, 2:22 a.m. πŸ”„ Last Modified: April 13, 2026, 5:49 p.m.
Total resulsts: 344974
Page 104 of 34,498
Β« previous page Β» next page
Filters