5.3

CVSS3.1

CVE-2026-35179 - WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts user-controlled parameters including an access tokenโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:05 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

9.3

CVSS4.0

CVE-2026-35178 - Workbench Affected by Remote Code Execution (RCE) via Malicious Cookie in Timezone Conversion

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerability in the timezone conversion flow, which processes attacker-controlled cookie values in an unsaโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:01 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:04 p.m.

5.1

CVSS4.0

CVE-2026-5679 - Totolink A3300R cstecgi.cgi vsetTr069Cfg os command injection

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. The exploit has been disclosed publicly and may be used.

๐Ÿ“… Published: April 6, 2026, 7 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:54 a.m.

7.1

CVSS3.1

CVE-2026-35176 - openFPGALoader has a heap buffer overflow in POFParser::parseSection() via crafted .pof file

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in POFParser::parseSection() that allows out-of-bounds heap memory access when parsing a crafted .pof file. No FPGA hardware is required to trigger this vulnerability.

๐Ÿ“… Published: April 6, 2026, 6:59 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

9.3

CVSS4.0

CVE-2026-35022 - Anthropic Claude Code & Agent SDK OS Command Injection via Authentication Helper

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are executed using shell=true without input validation. Attackers who can influence authentication settings can inject shell metacharacteโ€ฆ

๐Ÿ“… Published: April 6, 2026, 6:59 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

8.4

CVSS4.0

CVE-2026-35021 - Anthropic Claude Code & Agent SDK OS Command Injection via promptEditor.ts

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions inโ€ฆ

๐Ÿ“… Published: April 6, 2026, 6:59 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

7.1

CVSS3.1

CVE-2026-35170 - openFPGALoader has a heap buffer overflow in BitParser::parseHeader() via crafted .bit file

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in BitParser::parseHeader() that allows out-of-bounds heap memory access when parsing a crafted .bit file. No FPGA hardware is required to trigger this vulnerability.

๐Ÿ“… Published: April 6, 2026, 6:59 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

8.6

CVSS4.0

CVE-2026-35020 - Anthropic Claude Code & Agent SDK OS Command Injection via TERMINAL Environment Variable

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows local attackers to execute arbitrary commands by manipulating the TERMINAL environment variable. Attackers can inject shell metacharaโ€ฆ

๐Ÿ“… Published: April 6, 2026, 6:58 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5678 - Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. The exploit has been maโ€ฆ

๐Ÿ“… Published: April 6, 2026, 6:45 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:05 p.m.

6.9

CVSS4.0

CVE-2026-5677 - Totolink A7100RU cstecgi.cgi CsteSystem os command injection

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection. The attack may be initiated remotely. The exploit has been releasโ€ฆ

๐Ÿ“… Published: April 6, 2026, 6:30 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:40 p.m.
Total resulsts: 343921
Page 136 of 34,393
ยซ previous page ยป next page
Filters