0.0

CVE-2026-31690 - firmware: thead: Fix buffer overflow and use standard endian macros

In the Linux kernel, the following vulnerability has been resolved: firmware: thead: Fix buffer overflow and use standard endian macros Addresses two issues in the TH1520 AON firmware protocol driver: 1. Fix a potential buffer overflow where the code used unsafe pointer arithmetic to access t…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 3:15 a.m.

7.5

CVSS3.1

CVE-2026-31256 -

A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream1/track2, the device fails to properly validate the Transport header field. When this header is impr…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 8 p.m.

9.8

CVSS3.1

CVE-2026-30352 -

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 9:17 a.m.

9.3

CVSS3.1

CVE-2026-42363 - GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with variou…

πŸ“… Published: April 26, 2026, 11:58 p.m. πŸ”„ Last Modified: April 26, 2026, 11:58 p.m.

8.7

CVSS4.0

CVE-2026-7068 - D-Link DIR-825 nmbd sserver.c NMBD_process buffer overflow

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated within the local network. The exploit is publicly available and might be used. T…

πŸ“… Published: April 26, 2026, 11:45 p.m. πŸ”„ Last Modified: April 26, 2026, 11:45 p.m.

6.9

CVSS4.0

CVE-2026-7067 - D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection

A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been publ…

πŸ“… Published: April 26, 2026, 11:30 p.m. πŸ”„ Last Modified: April 26, 2026, 11:30 p.m.

6.9

CVSS4.0

CVE-2026-7066 - choieastsea simple-openstack-mcp server.py exec_openstack os command injection

A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function exec_openstack of the file server.py. The manipulation results in os command injection. It is possible to launch the attack remotely. The exploit has be…

πŸ“… Published: April 26, 2026, 11:15 p.m. πŸ”„ Last Modified: April 26, 2026, 11:15 p.m.

6.9

CVSS4.0

CVE-2026-7065 - BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-side request …

A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the component Remote Upload API. The manipulation of the argument url leads to server-side request forgery. …

πŸ“… Published: April 26, 2026, 11 p.m. πŸ”„ Last Modified: April 26, 2026, 11 p.m.

6.9

CVSS4.0

CVE-2026-7064 - AgentDeskAI browser-tools-mcp browser-connector.ts os command injection

A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published an…

πŸ“… Published: April 26, 2026, 10:45 p.m. πŸ”„ Last Modified: April 26, 2026, 10:45 p.m.

6.9

CVSS4.0

CVE-2026-7063 - code-projects Employee Management System Endpoint eprocess.php sql injection

A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performing a manipulation of the argument pwd results in sql injection. The attack is possible to be carried …

πŸ“… Published: April 26, 2026, 10:30 p.m. πŸ”„ Last Modified: April 26, 2026, 10:30 p.m.
Total resulsts: 347742
Page 110 of 34,775
Β« previous page Β» next page
Filters