8.7

CVSS4.0

CVE-2026-2961 - D-Link DWR-M960 VPN Configuration Endpoint formVpnConfigSetup sub_4196C4 stack-based overflow

A vulnerability has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4196C4 of the file /boafrm/formVpnConfigSetup of the component VPN Configuration Endpoint. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack is possible to be carried …

πŸ“… Published: Feb. 23, 2026, 12:02 a.m. πŸ”„ Last Modified: April 17, 2026, 4:30 p.m.

8.7

CVSS4.0

CVE-2026-2960 - D-Link DWR-M960 formDhcpv6s sub_468D64 stack-based overflow

A flaw has been found in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_468D64 of the file /boafrm/formDhcpv6s. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and m…

πŸ“… Published: Feb. 23, 2026, 12:02 a.m. πŸ”„ Last Modified: April 17, 2026, 4:30 p.m.

4

CVSS3.1

CVE-2025-61146 -

saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.

πŸ“… Published: Feb. 23, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:15 p.m.

6.1

CVSS3.1

CVE-2026-26464 - Stored Cross‑Site Scripting in Society Management System Portal Allows Remote Script Injection

Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that is executed in users' browsers. This vulnerability can be exploited via the name parameter in a POS…

πŸ“… Published: Feb. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 7:45 p.m.

7.4

CVSS3.1

CVE-2025-70045 -

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTPS request options when 'jx_obj.IsSecure' is true

πŸ“… Published: Feb. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:03 p.m.

7.4

CVSS3.1

CVE-2025-63945 -

A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

πŸ“… Published: Feb. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 4:31 p.m.

9.8

CVSS3.1

CVE-2025-61144 - libtiff: libtiff: Denial of Service via buffer overflow

libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.

πŸ“… Published: Feb. 23, 2026, midnight πŸ”„ Last Modified: Feb. 25, 2026, 3:20 p.m.

8.8

CVSS3.1

CVE-2026-3062 - chromium-browser: Out of bounds read and write in Tint

Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Feb. 23, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 4:15 p.m.

8.8

CVSS3.1

CVE-2026-3061 - chromium-browser: Out of bounds read in Media

Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Feb. 23, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 4:15 p.m.

8

CVSS3.1

CVE-2025-70329 -

TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without adequate validation o…

πŸ“… Published: Feb. 23, 2026, midnight πŸ”„ Last Modified: Feb. 24, 2026, 8:38 p.m.
Total resulsts: 349182
Page 1486 of 34,919
Β« previous page Β» next page
Filters