5.1

CVSS4.0

CVE-2019-25382 - Smoothwall Express 3.1 'time.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the NTP_SERVER parameter. Attackers can send POST requests to the time.cgi endpoint with script payloads in the N…

πŸ“… Published: Feb. 16, 2026, 5:04 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25381 - Smoothwall Express 3.1 'hosts.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests to the hosts.cgi endpoint with script payloads…

πŸ“… Published: Feb. 16, 2026, 5:04 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25380 - Smoothwall Express 3.1 'dhcp.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dhcp.cgi script that allow attackers to inject malicious scripts through multiple parameters. Attackers can submit POST requests to dhcp.cgi with script payloads in parameters suc…

πŸ“… Published: Feb. 16, 2026, 5:04 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.3

CVSS4.0

CVE-2019-25379 - Smoothwall Express 3.1 'urlfilter.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attackers can submit POST requests with script payloads in the REDIRECT_PAGE or CHILDREN parameters to e…

πŸ“… Published: Feb. 16, 2026, 5:04 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25378 - Smoothwall Express 3.1 'proxy.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple cross-site scripting vulnerabilities in the proxy.cgi endpoint that allow attackers to inject malicious scripts through parameters including CACHE_SIZE, MAX_SIZE, MIN_SIZE, MAX_OUTGOING_SIZE, and MAX_INCOMING_SIZE. Attackers can subm…

πŸ“… Published: Feb. 16, 2026, 5:04 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

8.6

CVSS4.0

CVE-2026-2566 - Wavlink WL-NU516U1 adm.cgi sub_406194 stack-based overflow

A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260. This affects the function sub_406194 of the file /cgi-bin/adm.cgi. Such manipulation of the argument firmware_url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed…

πŸ“… Published: Feb. 16, 2026, 5:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 10:12 a.m.

7.5

CVSS4.0

CVE-2026-2565 - Wavlink WL-NU516U1 adm.cgi sub_40785C stack-based overflow

A weakness has been identified in Wavlink WL-NU516U1 20251208. Affected by this issue is the function sub_40785C of the file /cgi-bin/adm.cgi. This manipulation of the argument time_zone causes stack-based buffer overflow. The attack can be initiated remotely. The attack is considered to have high …

πŸ“… Published: Feb. 16, 2026, 4:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 10:12 a.m.

7.2

CVSS3.1

CVE-2026-26930 -

SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.

πŸ“… Published: Feb. 16, 2026, 4:27 p.m. πŸ”„ Last Modified: Feb. 22, 2026, 8:15 p.m.

8.7

CVSS3.1

CVE-2026-2101 - Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Ve…

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's browser session.

πŸ“… Published: Feb. 16, 2026, 4:02 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 5:52 p.m.

9.2

CVSS4.0

CVE-2026-2564 - Intelbras VIP 3260 Z IA OutsideCmd password recovery

A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly c…

πŸ“… Published: Feb. 16, 2026, 4:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 10:12 a.m.
Total resulsts: 343887
Page 1090 of 34,389
Β« previous page Β» next page
Filters