5.1

CVSS4.0

CVE-2026-2898 - funadmin Backend Endpoint AuthCloudService.php getMember deserialization

A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserialization. The attack may be performed from remo…

πŸ“… Published: Feb. 22, 2026, 12:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 4:27 p.m.

4.8

CVSS4.0

CVE-2026-2897 - funadmin Backend index.html cross site scripting

A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross site scripting. The attack is possible to be carrie…

πŸ“… Published: Feb. 22, 2026, 12:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 4:35 p.m.

6.9

CVSS4.0

CVE-2026-2896 - funadmin Configuration Ajax.php setConfig improper authorization

A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been …

πŸ“… Published: Feb. 21, 2026, 11:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 4:38 p.m.

6.3

CVSS4.0

CVE-2026-2895 - funadmin Member.php repass password recovery

A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery. Remote exploitation of the attack is possib…

πŸ“… Published: Feb. 21, 2026, 11:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 4:42 p.m.

6.9

CVSS4.0

CVE-2026-2894 - funadmin forget.html getMember information disclosure

A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. The exploit is publicly available and might b…

πŸ“… Published: Feb. 21, 2026, 11:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 4:48 p.m.

4.8

CVSS4.0

CVE-2026-2889 - CCExtractor mp4.c processmp4 use after free

A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 …

πŸ“… Published: Feb. 21, 2026, 10:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2026-2887 - aardappel lobster idents.h TypeName recursion

A security vulnerability has been detected in aardappel lobster up to 2025.4. This impacts the function lobster::TypeName in the library dev/src/lobster/idents.h. Such manipulation leads to uncontrolled recursion. The attack can only be performed from a local environment. The exploit has been discl…

πŸ“… Published: Feb. 21, 2026, 9:02 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 9:41 p.m.

8.7

CVSS4.0

CVE-2026-2886 - Tenda A21 SetOnlineDevName set_device_name stack-based overflow

A weakness has been identified in Tenda A21 1.0.0.0. This affects the function set_device_name of the file /goform/SetOnlineDevName. This manipulation of the argument devName causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to t…

πŸ“… Published: Feb. 21, 2026, 9:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9 p.m.

8.7

CVSS4.0

CVE-2026-2885 - D-Link DWR-M960 formIpv6Setup sub_469104 stack-based overflow

A security flaw has been discovered in D-Link DWR-M960 1.01.07. The impacted element is the function sub_469104 of the file /boafrm/formIpv6Setup. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been releas…

πŸ“… Published: Feb. 21, 2026, 8:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 7:37 p.m.

8.7

CVSS4.0

CVE-2026-2884 - D-Link DWR-M960 WAN Interface Setting formWanConfigSetup sub_41914C stack-based overflow

A vulnerability was identified in D-Link DWR-M960 1.01.07. The affected element is the function sub_41914C of the file /boafrm/formWanConfigSetup of the component WAN Interface Setting Handler. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack is possible …

πŸ“… Published: Feb. 21, 2026, 8:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 7:38 p.m.
Total resulsts: 344690
Page 1047 of 34,469
Β« previous page Β» next page
Filters