5.1

CVSS4.0

CVE-2026-27512 - Tenda F3 Reflected Script Execution via Missing nosniff Header

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the response body. Under affect…

📅 Published: Feb. 23, 2026, 4:26 p.m. 🔄 Last Modified: April 18, 2026, 11:15 a.m.

5.1

CVSS4.0

CVE-2026-27511 - Tenda F3 Clickjacking in Web Management Interface

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to embed administrative pages in an iframe and trick an authentica…

📅 Published: Feb. 23, 2026, 4:25 p.m. 🔄 Last Modified: April 16, 2026, 4:45 p.m.

7.6

CVSS3.1

CVE-2026-22567 - ZIA Admin UI Input Validation Bug

Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.

📅 Published: Feb. 23, 2026, 4:13 p.m. 🔄 Last Modified: April 17, 2026, 4:30 p.m.

5.5

CVSS3.1

CVE-2026-22568 - Unauthorized information retrieval in ZIA Admin UI

Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare conditions.

📅 Published: Feb. 23, 2026, 4:12 p.m. 🔄 Last Modified: April 18, 2026, 11:15 a.m.

2.1

CVSS4.0

CVE-2026-2697 - Indirect Object Reference (IDOR) in Security Center

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

📅 Published: Feb. 23, 2026, 3:17 p.m. 🔄 Last Modified: April 18, 2026, 11:15 a.m.

8.7

CVSS4.0

CVE-2026-3016 - UTT HiPER 810G formP2PLimitConfig strcpy buffer overflow

A vulnerability was identified in UTT HiPER 810G up to 1.7.7-171114. The affected element is the function strcpy of the file /goform/formP2PLimitConfig. The manipulation of the argument except leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available…

📅 Published: Feb. 23, 2026, 3:02 p.m. 🔄 Last Modified: April 17, 2026, 4:30 p.m.

8.7

CVSS4.0

CVE-2026-3015 - UTT HiPER 810G formPolicyRouteConf strcpy buffer overflow

A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/formPolicyRouteConf. Executing a manipulation of the argument GroupName can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed …

📅 Published: Feb. 23, 2026, 2:32 p.m. 🔄 Last Modified: April 18, 2026, 6 p.m.

7.3

CVSS3.1

CVE-2026-21420 - Local Privilege Escalation via Uncontrolled Search Path in Dell Repository Manager

Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution and escalation of privileges.

📅 Published: Feb. 23, 2026, 2:01 p.m. 🔄 Last Modified: April 18, 2026, 11:15 a.m.

5.9

CVSS3.1

CVE-2025-59873 - Session Token Exposure via URL Query Parameters

An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site linked from the applica…

📅 Published: Feb. 23, 2026, 10:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2026-2985 - Tiandy Video Surveillance System 视频监控平台 CLSBODownLoad.java downloadImage server-side request forgery

A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloadImage of the file /com/tiandy/easy7/core/bo/CLSBODownLoad.java. Performing a manipulation of the argument urlPath results in server-side request forgery. The attack is possible t…

📅 Published: Feb. 23, 2026, 10:32 a.m. 🔄 Last Modified: April 17, 2026, 4:30 p.m.
Total resulsts: 349182
Page 1482 of 34,919
« previous page » next page
Filters