9.8

CVSS3.1

CVE-2026-26704 -

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: April 17, 2026, 1:45 p.m.

4.9

CVSS3.1

CVE-2026-26698 - Simple Student Alumni System v1.0 SQL Injection in TracerStudy/modal_edit.php

code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: April 17, 2026, 1:45 p.m.

9.8

CVSS3.1

CVE-2026-24110 - Buffer Overflow via Overly Long addDhcpRules Input in Tenda W20E Firmware

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule, " %d\t%[^\t]\t%[^\n\r\t]", &dhcpsIndex, dhcpsIP, dhcpsMac);`, the lack of size validation for the โ€ฆ

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 2:45 p.m.

9.8

CVSS3.1

CVE-2026-26712 - SQL Injection in Simple Food Order System Admin Ticket View Endpoint

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 3 p.m.

9.8

CVSS3.1

CVE-2026-24115 - Buffer Overflow in Tenda W20E Firmware via Improper Size Validation

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstruleQos` may lead to buffer overflow.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 3 p.m.

6.1

CVSS3.1

CVE-2025-66880 -

Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute arbitrary code via the LoginComp (Module 2093) and SignupComp (Module 2094) modules.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: March 3, 2026, 8:46 a.m.

7.5

CVSS3.1

CVE-2025-70252 -

An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: March 6, 2026, 9:04 p.m.

9.8

CVSS3.1

CVE-2026-24101 - Command Injection in Tenda AC15 Router FormSetIptv

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 2:45 p.m.

7.5

CVSS3.1

CVE-2026-24114 - Buffer Overflow via Unvalidated Port Mapping Index in Tenda W20E Firmware

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 3 p.m.

9.8

CVSS3.1

CVE-2026-24107 - Critical Command Injection via USB Partition Parameter in Tenda W20E Router

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities.

๐Ÿ“… Published: March 2, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 3 p.m.
Total resulsts: 349182
Page 1390 of 34,919
ยซ previous page ยป next page
Filters