5.1

CVSS4.0

CVE-2025-15543 - Read-Only Root Access via USB Storage Device in TP-Link VX800v

Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem contents, giving an attacker with physical access readโ€‘only access to system files.

๐Ÿ“… Published: Jan. 29, 2026, 6:06 p.m. ๐Ÿ”„ Last Modified: March 9, 2026, 5:52 p.m.

6.3

CVSS4.0

CVE-2025-15542 - Denial of Service (DoS) of VoIP Communication on TP-Link VX800v

Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with crafted INVITE messages, blocking all voice lines and causing a denial of service on incoming calls.

๐Ÿ“… Published: Jan. 29, 2026, 6:06 p.m. ๐Ÿ”„ Last Modified: March 9, 2026, 5:52 p.m.

6.9

CVSS4.0

CVE-2025-15541 - Access to System Files via SFTP on TP-Link VX800v

Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.

๐Ÿ“… Published: Jan. 29, 2026, 6:05 p.m. ๐Ÿ”„ Last Modified: March 9, 2026, 5:51 p.m.

7.7

CVSS4.0

CVE-2025-13399 - Insecure Encryption in Communication with the Web Interface on TP-Link VX800v

A weakness in the web interfaceโ€™s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force the weak AES key and decrypt intercepted traffic. Successful exploitation requires network proximity but no authentication, and may result in high impact to confidentiality, inteโ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, 6:05 p.m. ๐Ÿ”„ Last Modified: March 9, 2026, 5:51 p.m.

5.3

CVSS4.0

CVE-2026-1600 - Bdtask Bhojon All-In-One Restaurant Management System Add-to-Cart Submission Endpoint addtocart logโ€ฆ

A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart of the component Add-to-Cart Submission Endpoint. The manipulation of the argument price/allprice leads to business logicโ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, 6:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:30 a.m.

8.6

CVSS4.0

CVE-2026-24780 - AutoGPT is Vulnerable to RCE via Disabled Block Execution

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UUID wโ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, 5:39 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:30 a.m.

6.8

CVSS4.0

CVE-2026-24414 - Icinga for Windows certificate can have too-open permissions

The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in โ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, 5:35 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:45 p.m.

5.3

CVSS4.0

CVE-2026-1599 - Bdtask Bhojon All-In-One Restaurant Management System Checkout placeorder logic error

A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected element is an unknown function of the file /hungry/placeorder of the component Checkout. Executing a manipulation of the argument orggrandTotal/vat/service_charge/grandtotal can leadโ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, 5:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:30 a.m.

7.3

CVSS4.0

CVE-2025-15545 - Insufficient Backup File Upload Input Validation on TP-Link Archer RE605X

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attackerโ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, 5:31 p.m. ๐Ÿ”„ Last Modified: March 9, 2026, 4:55 p.m.

6.8

CVSS4.0

CVE-2026-24413 - Icinga has insecure permission of %ProgramData%\icinga2\var on Windows

Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of theโ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, 5:21 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:45 p.m.
Total resulsts: 347398
Page 1713 of 34,740
ยซ previous page ยป next page
Filters