7.5

CVSS3.1

CVE-2025-46115 - Remote Denial of Service via Crafted PDU Session Modification Request in Open5GS 2.7.3

An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 4, 2026, 10 p.m.

7.5

CVSS3.1

CVE-2026-36959 - Unrestricted Bruteโ€‘Force Login on Uโ€‘SPEED N300 Router

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorizedโ€ฆ

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 3 a.m.

7.5

CVSS3.1

CVE-2026-36958 - Denial of Service via HTTP Flood on Uโ€‘SPEED N300 Router

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the rโ€ฆ

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 3 a.m.

7.5

CVSS3.1

CVE-2026-36957 - Denial of Service via Resource Exhaustion on Dbit N300 T1 Pro Router

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffeโ€ฆ

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 2:59 a.m.

8.8

CVSS3.1

CVE-2026-36956 - Crossโ€‘Site Request Forgery in Dbit N300 T1 Pro Router Web Management

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An โ€ฆ

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 12:09 a.m.

10

CVSS3.1

CVE-2026-36767 - Arbitrary File Write via Path Traversal in Shopizer Image Upload

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 2, 2026, 12:30 a.m.

8.8

CVSS3.1

CVE-2026-36762 -

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations.

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 4, 2026, 8 p.m.

8.8

CVSS3.1

CVE-2026-36765 -

An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 4, 2026, 8 p.m.

6.5

CVSS3.1

CVE-2026-40685 -

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 2, 2026, 8:15 a.m.

3.7

CVSS3.1

CVE-2026-40686 -

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.

๐Ÿ“… Published: April 30, 2026, midnight ๐Ÿ”„ Last Modified: May 1, 2026, 2:27 p.m.
Total resulsts: 349182
Page 196 of 34,919
ยซ previous page ยป next page
Filters