7.5
CVE-2026-23864 - react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Coβ¦
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, aβ¦
8.5
CVE-2025-14756 - Authenticated Command Injection Vulnerability in Archer MR600
Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or fβ¦
0.0
CVE-2026-1452 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
7.1
CVE-2025-71178 - Crucial Storage Executive < 11.08.082025.00 Installer DLL Preloading LPE
Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which can cause a malicious DLL placed alongside the installer to β¦
2.7
CVE-2026-0925 - Tanium addressed an improper input validation vulnerability in Discover.
Tanium addressed an improper input validation vulnerability in Discover.
7.1
CVE-2026-24435 - Tenda W30E V2 Permissive CORS Allows Cross-origin Data Access
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets Access-Control-Allow-Origin: * in combination with Access-Control-Allow-Credentials: true, alloβ¦
2.1
CVE-2026-24439 - Tenda W30E V2 Lacks X-Content-Type-Options Header
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable scrβ¦
4
CVE-2025-57784 - Tomahawk authentication timing attack due to usage of 'strcmp'
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
5.1
CVE-2026-24432 - Tenda W30E V2 Missing CSRF Protections for Administrative Actions
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggeredβ¦
6.5
CVE-2025-57785 - Double free in XSLT in 'show_index'
A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.