6.9

CVSS4.0

CVE-2026-7058 - 666ghj MiroFish Inter-Process Communication simulation_ipc.py SimulationIPCClient.send_command comm…

A vulnerability has been found in 666ghj MiroFish up to 0.1.2. The impacted element is the function SimulationIPCClient.send_command of the file backend/app/services/simulation_ipc.py of the component Inter-Process Communication. Such manipulation leads to command injection. It is possible to launc…

📅 Published: April 26, 2026, 7:45 p.m. 🔄 Last Modified: April 26, 2026, 7:45 p.m.

8.7

CVSS4.0

CVE-2026-7057 - Tenda F456 httpd setcfm buffer overflow

A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and…

📅 Published: April 26, 2026, 6:45 p.m. 🔄 Last Modified: April 26, 2026, 6:45 p.m.

8.7

CVSS4.0

CVE-2026-7056 - Tenda F456 httpd SafeUrlFilter fromSafeUrlFilter buffer overflow

A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be us…

📅 Published: April 26, 2026, 6:30 p.m. 🔄 Last Modified: April 26, 2026, 6:30 p.m.

8.7

CVSS4.0

CVE-2026-7055 - Tenda F456 httpd VirtualSer fromVirtualSer buffer overflow

A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The e…

📅 Published: April 26, 2026, 6 p.m. 🔄 Last Modified: April 26, 2026, 6 p.m.

8.7

CVSS4.0

CVE-2026-7054 - Tenda F456 httpd PPTPDClient fromPptpUserAdd buffer overflow

A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usernamewith can lead to buffer overflow. The attack can be executed remotely. The e…

📅 Published: April 26, 2026, 4:45 p.m. 🔄 Last Modified: April 26, 2026, 4:45 p.m.

8.7

CVSS4.0

CVE-2026-7053 - Tenda F456 httpd L7Prot frmL7ProtForm buffer overflow

A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been releas…

📅 Published: April 26, 2026, 4 p.m. 🔄 Last Modified: April 26, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-7045 - baomidou dynamic-datasource StandardEvaluationContext/SpelExpressionParser DsSpelExpressionProcesso…

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the com…

📅 Published: April 26, 2026, 1:45 p.m. 🔄 Last Modified: April 26, 2026, 1:45 p.m.

5.3

CVSS4.0

CVE-2026-7044 - GreenCMS index.php themeadd unrestricted upload

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability only af…

📅 Published: April 26, 2026, 1:30 p.m. 🔄 Last Modified: April 26, 2026, 1:30 p.m.

6.9

CVSS4.0

CVE-2018-25297 - Wansview 1.0.2 Denial of Service via Buffer Overflow

Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads into the Camera name and DID number fields during camera addition to trigger application crashes.

📅 Published: April 26, 2026, 1:19 p.m. 🔄 Last Modified: April 26, 2026, 1:19 p.m.

6.8

CVSS4.0

CVE-2018-25296 - P10 Central Management Software 1.4.13 Denial of Service

P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 2000-byte payload into the password field and click login to trigger an app…

📅 Published: April 26, 2026, 1:19 p.m. 🔄 Last Modified: April 26, 2026, 1:19 p.m.
Total resulsts: 347748
Page 112 of 34,775
« previous page » next page
Filters