9.3

CVSS4.0

CVE-2017-20223 - Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference

Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: March 16, 2026, 1:28 a.m.

8.7

CVSS4.0

CVE-2017-20222 - Telesquare SKT LTE Router SDT-CS3B1 Unauthenticated Remote Reboot

Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger device reboot without authentication. Attackers can send POST requests to the lte.cgi endpoint with the Command=Reboot parameter to cause denial of ser…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: March 16, 2026, 1:28 a.m.

5.3

CVSS4.0

CVE-2017-20221 - Telesquare SKT LTE Router SDT-CS3B1 CSRF System Command Execution

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting missing request validation. Attackers can craft malicious web pages that perform administrative actions when v…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: March 16, 2026, 1:28 a.m.

5.3

CVSS4.0

CVE-2026-4204 - D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_myfavor…

📅 Published: March 16, 2026, 1:02 a.m. 🔄 Last Modified: March 16, 2026, 1:02 a.m.

5.3

CVSS4.0

CVE-2026-4203 - D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_portforwardi…

📅 Published: March 16, 2026, 1:02 a.m. 🔄 Last Modified: March 16, 2026, 1:02 a.m.

6.9

CVSS4.0

CVE-2026-4201 - glowxq glowxq-oj SysFileController.java upload unrestricted upload

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of the file business/business-system/src/main/java/com/glowxq/system/admin/controller/SysFileController.java. Executing a manipulation can lead to unrest…

📅 Published: March 16, 2026, 12:32 a.m. 🔄 Last Modified: March 16, 2026, 6:47 p.m.

6.9

CVSS4.0

CVE-2026-4200 - glowxq glowxq-oj ProblemCaseController.java uploadTestcaseZipUrl server-side request forgery

A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This affects the function uploadTestcaseZipUrl of the file business/business-oj/src/main/java/com/glowxq/oj/problem/controller/ProblemCaseController.java. Performing a manipulation results in ser…

📅 Published: March 16, 2026, 12:02 a.m. 🔄 Last Modified: March 16, 2026, 8:04 p.m.

4.8

CVSS4.0

CVE-2026-4199 - bazinga012 mcp_code_executor index.ts installDependencies command injection

A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function installDependencies of the file src/index.ts. Such manipulation leads to command injection. The attack can only be performed from a local environment. The exploit is publicly available…

📅 Published: March 16, 2026, 12:02 a.m. 🔄 Last Modified: March 16, 2026, 8:06 p.m.

5.4

CVSS3.1

CVE-2025-69693 - FFmpeg: out-of-bounds read in RV60 video decoder

Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from…

📅 Published: March 16, 2026, midnight 🔄 Last Modified: March 16, 2026, 9:16 p.m.

0.0

CVE-2025-69902 -

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

📅 Published: March 16, 2026, midnight 🔄 Last Modified: March 16, 2026, 9:16 p.m.
Total resulsts: 338261
Page 19 of 33,827
« previous page » next page
Filters