5

CVSS3.1

CVE-2026-22716 - VMware Workstation out-of-bounds write vulnerability

Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes.

📅 Published: Feb. 27, 2026, 7:01 p.m. 🔄 Last Modified: April 16, 2026, 3:30 p.m.

8.2

CVSS4.0

CVE-2026-2880 - @fastify/middie has an improper path normalization vulnerability

A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example, app.use('/secret', auth)). When Fastify router normalization options are enabled (such as ignoreDuplicateSlashes, useSemicolonDelimiter, and related…

📅 Published: Feb. 27, 2026, 6:25 p.m. 🔄 Last Modified: April 17, 2026, 2 p.m.

5.1

CVSS4.0

CVE-2026-27758 - SODOLA SL902-SWTGW124AS <= 200.1.20 Missing CSRF Protections

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows attackers to induce authenticated users into submitting forged requests. Attackers can craft malicious requests that execute unauthorized configurati…

📅 Published: Feb. 27, 2026, 6:11 p.m. 🔄 Last Modified: April 17, 2026, 2 p.m.

7.1

CVSS4.0

CVE-2026-27757 - SODOLA SL902-SWTGW124AS <= 200.1.20 Unverified Password Change

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenticated session can modify credentials to maintain persistent …

📅 Published: Feb. 27, 2026, 6:11 p.m. 🔄 Last Modified: April 17, 2026, 2 p.m.

5.1

CVSS4.0

CVE-2026-27756 - SODOLA SL902-SWTGW124AS <= 200.1.20 Reflected XSS in Management Interface

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft malicious URLs that execute arbitrary JavaScript in the web interface when visite…

📅 Published: Feb. 27, 2026, 6:10 p.m. 🔄 Last Modified: April 17, 2026, 2 p.m.

9.3

CVSS4.0

CVE-2026-27755 - SODOLA SL902-SWTGW124AS <= 200.1.20 Predictable Session ID

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies. Attackers who know or guess valid credentials can calculate the session identifier …

📅 Published: Feb. 27, 2026, 6:09 p.m. 🔄 Last Modified: April 16, 2026, 3:30 p.m.

6.9

CVSS4.0

CVE-2026-27754 - SODOLA SL902-SWTGW124AS <= 200.1.20 MD5 Session Token Generation

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for session cookie generation, weakening session security. Attackers can exploit predictable session tokens combined with MD5's collision vulnerabilities to forge valid session cookies and …

📅 Published: Feb. 27, 2026, 6:09 p.m. 🔄 Last Modified: April 16, 2026, 3:30 p.m.

6.9

CVSS4.0

CVE-2026-27753 - SODOLA SL902-SWTGW124AS <= 200.1.20 Improper Login Rate Limiting

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unlimited login attempts against the management interface. Attackers can conduct online password guessing attacks without account lockout or rate limitin…

📅 Published: Feb. 27, 2026, 6:09 p.m. 🔄 Last Modified: April 17, 2026, 2 p.m.

8.2

CVSS4.0

CVE-2026-27752 - SODOLA SL902-SWTGW124AS <= 200.1.20 Cleartext Credential Transmission

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse them to gain administr…

📅 Published: Feb. 27, 2026, 6:08 p.m. 🔄 Last Modified: April 16, 2026, 3:30 p.m.

9.3

CVSS4.0

CVE-2026-27751 - SODOLA SL902-SWTGW124AS <= 200.1.20 Use of Default Credentials

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to …

📅 Published: Feb. 27, 2026, 6:07 p.m. 🔄 Last Modified: April 16, 2026, 3:30 p.m.
Total resulsts: 349182
Page 1402 of 34,919
« previous page » next page
Filters