6.9

CVSS4.0

CVE-2026-1687 - Tenda HG10 Boa Webserver formSamba command injection

A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of the component Boa Webserver. Executing a manipulation of the argument serverString can lead to command injection. It is possible to launch the attack r…

📅 Published: Jan. 30, 2026, 4:02 p.m. 🔄 Last Modified: April 18, 2026, 1:15 a.m.

8.6

CVSS3.1

CVE-2025-4686 - Time-Based Blind SQLi in Kodmatic Computer's Online Exam and Assessment

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry and Trade Ltd. Co. Online Exam and Assessment allows SQL Injection.This issue affects Online Exam and Assessment: through 30012026.  NOTE: …

📅 Published: Jan. 30, 2026, 3:54 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2026-25128 - fast-xml-parser has RangeError DoS Numeric Entities Bug

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range …

📅 Published: Jan. 30, 2026, 3:14 p.m. 🔄 Last Modified: April 18, 2026, 1:15 a.m.

2.7

CVSS4.0

CVE-2026-25050 - Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy

Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses). In `packages/core/src/config/auth/native-authentication-strat…

📅 Published: Jan. 30, 2026, 3:11 p.m. 🔄 Last Modified: April 18, 2026, 1:15 a.m.

7.2

CVSS4.0

CVE-2026-24855 - ChurchCRM has Stored Cross-Site Scripting (XSS) in Create Events in Church Calendar, Leading to Acc…

ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description field. This payload is stored in the database, and wh…

📅 Published: Jan. 30, 2026, 3:08 p.m. 🔄 Last Modified: April 18, 2026, 1:15 a.m.

8.8

CVSS3.1

CVE-2026-24854 - Church CRM has SQL injection in PaddleNumEditor.php

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6…

📅 Published: Jan. 30, 2026, 3:05 p.m. 🔄 Last Modified: April 18, 2026, 1:15 a.m.

9.2

CVSS4.0

CVE-2025-7964 - Zigbee Router Denial of Service

After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to rejoin. A manual recommi…

📅 Published: Jan. 30, 2026, 3:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2026-1686 - Totolink A3600R app.so setAppEasyWizardConfig buffer overflow

A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. Performing a manipulation of the argument apcliSsid results in buffer overflow. It is possible to initiate the attack remotely. The explo…

📅 Published: Jan. 30, 2026, 3:02 p.m. 🔄 Last Modified: April 18, 2026, 1:15 a.m.

6.3

CVSS4.0

CVE-2026-1685 - D-Link DIR-823X Login sub_40AC74 excessive authentication

A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high co…

📅 Published: Jan. 30, 2026, 2:32 p.m. 🔄 Last Modified: April 18, 2026, 1:15 a.m.

6.9

CVSS4.0

CVE-2026-1684 - Free5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of service

A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can be executed remotely. It is advisable to impleme…

📅 Published: Jan. 30, 2026, 2:32 p.m. 🔄 Last Modified: April 18, 2026, 1:15 a.m.
Total resulsts: 347438
Page 1710 of 34,744
« previous page » next page
Filters