7.5

CVSS3.1

CVE-2026-23864 - react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Co…

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, a…

πŸ“… Published: Jan. 26, 2026, 7:16 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 a.m.

8.5

CVSS4.0

CVE-2025-14756 - Authenticated Command Injection Vulnerability in Archer MR600

Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or f…

πŸ“… Published: Jan. 26, 2026, 6:17 p.m. πŸ”„ Last Modified: March 9, 2026, 2:07 p.m.

0.0

CVE-2026-1452 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Jan. 26, 2026, 6:15 p.m. πŸ”„ Last Modified: Feb. 17, 2026, 5:26 p.m.

7.1

CVSS4.0

CVE-2025-71178 - Crucial Storage Executive < 11.08.082025.00 Installer DLL Preloading LPE

Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which can cause a malicious DLL placed alongside the installer to …

πŸ“… Published: Jan. 26, 2026, 5:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2026-0925 - Tanium addressed an improper input validation vulnerability in Discover.

Tanium addressed an improper input validation vulnerability in Discover.

πŸ“… Published: Jan. 26, 2026, 5:51 p.m. πŸ”„ Last Modified: April 18, 2026, 3:15 p.m.

7.1

CVSS4.0

CVE-2026-24435 - Tenda W30E V2 Permissive CORS Allows Cross-origin Data Access

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets Access-Control-Allow-Origin: * in combination with Access-Control-Allow-Credentials: true, allo…

πŸ“… Published: Jan. 26, 2026, 5:49 p.m. πŸ”„ Last Modified: April 16, 2026, 5:45 p.m.

2.1

CVSS4.0

CVE-2026-24439 - Tenda W30E V2 Lacks X-Content-Type-Options Header

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable scr…

πŸ“… Published: Jan. 26, 2026, 5:48 p.m. πŸ”„ Last Modified: April 16, 2026, 5:45 p.m.

4

CVSS3.1

CVE-2025-57784 - Tomahawk authentication timing attack due to usage of 'strcmp'

Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.

πŸ“… Published: Jan. 26, 2026, 5:47 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 2:16 p.m.

5.1

CVSS4.0

CVE-2026-24432 - Tenda W30E V2 Missing CSRF Protections for Administrative Actions

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggered…

πŸ“… Published: Jan. 26, 2026, 5:46 p.m. πŸ”„ Last Modified: April 16, 2026, 5:45 p.m.

6.5

CVSS3.1

CVE-2025-57785 - Double free in XSLT in 'show_index'

A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.

πŸ“… Published: Jan. 26, 2026, 5:46 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 3:21 p.m.
Total resulsts: 349182
Page 1945 of 34,919
Β« previous page Β» next page
Filters