5.1

CVSS4.0

CVE-2026-34798 - Endian Firewall /cgi-bin/routing.cgi remark Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

8.7

CVSS4.0

CVE-2026-34797 - Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injection

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete rโ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

8.7

CVSS4.0

CVE-2026-34796 - Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injection

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incompletโ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

8.7

CVSS4.0

CVE-2026-34795 - Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injection

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete reโ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

8.7

CVSS4.0

CVE-2026-34794 - Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injection

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete reโ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

8.7

CVSS4.0

CVE-2026-34793 - Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injection

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incompleโ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

8.7

CVSS4.0

CVE-2026-34792 - Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injection

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incompleteโ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

8.7

CVSS4.0

CVE-2026-34791 - Endian Firewall /cgi-bin/logs_proxy.cgi DATE Perl Command Injection

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete โ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

7.1

CVSS4.0

CVE-2026-34790 - Endian Firewall /cgi-bin/backup.cgi remove ARCHIVE Directory Traversal

Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, whiโ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.3

CVSS4.0

CVE-2026-5344 - Textpattern XML-RPC TXP_RPCServer.php mt_uploadImage path traversal

A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt_uploadImage of the file rpc/TXP_RPCServer.php of the component XML-RPC Handler. The manipulation of the argument file.name leads to path traversal. Remote exploitation of the attโ€ฆ

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 2:45 p.m.
Total resulsts: 341937
Page 14 of 34,194
ยซ previous page ยป next page
Filters