5.3

CVSS4.0

CVE-2026-7687 - langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injecti…

A vulnerability was determined in langflow-ai langflow up to 1.8.4. Affected by this issue is the function CodeParser.parse_callable_details of the file src/lfx/src/lfx/custom/code_parser/code_parser.py of the component Full Builtins Module Handler. Executing a manipulation can lead to command inje…

📅 Published: May 3, 2026, 8:45 a.m. 🔄 Last Modified: May 3, 2026, 8:45 a.m.

6.9

CVSS4.0

CVE-2026-7686 - eyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access control

A vulnerability was found in eyeo Adblock Plus up to 4.36.2 on Chrome. Affected by this vulnerability is the function postMessage of the file premium.preload.js of the component Legacy Premium Activation. Performing a manipulation results in improper access controls. Remote exploitation of the atta…

📅 Published: May 3, 2026, 7:30 a.m. 🔄 Last Modified: May 3, 2026, 7:30 a.m.

8.7

CVSS4.0

CVE-2026-7685 - Edimax BR-6208AC setWAN buffer overflow

A vulnerability was detected in Edimax BR-6208AC up to 1.02. Affected is an unknown function of the file /goform/setWAN. Performing a manipulation of the argument pptpDfGateway  results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor w…

📅 Published: May 3, 2026, 7 a.m. 🔄 Last Modified: May 3, 2026, 7 a.m.

8.7

CVSS4.0

CVE-2026-7684 - Edimax BR-6428nC setWAN buffer overflow

A security vulnerability has been detected in Edimax BR-6428nC up to 1.16. This impacts an unknown function of the file /goform/setWAN. Such manipulation of the argument pptpDfGateway  leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be …

📅 Published: May 3, 2026, 6:45 a.m. 🔄 Last Modified: May 3, 2026, 6:45 a.m.

5.3

CVSS4.0

CVE-2026-7683 - Edimax BR-6428nC Web setWAN command injection

A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the argument pppUserName/pptpUserName causes command injection. The attack can be initiated remotely. The exploit has been …

📅 Published: May 3, 2026, 6:30 a.m. 🔄 Last Modified: May 3, 2026, 6:30 a.m.

5.3

CVSS4.0

CVE-2026-7682 - Edimax BR-6208AC L2TP Mode setWAN command injection

A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has …

📅 Published: May 3, 2026, 6:15 a.m. 🔄 Last Modified: May 3, 2026, 6:15 a.m.

0.0

CVE-2026-5337 - Frontend File Manager Plugin <= 23.6 - Subscriber+ Arbitrary Download Access via IDOR

During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly valida…

📅 Published: May 3, 2026, 6 a.m. 🔄 Last Modified: May 3, 2026, 6 a.m.

6.9

CVSS4.0

CVE-2026-7681 - jsbroks COCO Annotator Dataset API datasets.py authorization

A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the file backend/webserver/api/datasets.py of the component Dataset API. The manipulation of the argument DatasetId leads to authorization bypass. The att…

📅 Published: May 3, 2026, 5 a.m. 🔄 Last Modified: May 3, 2026, 5 a.m.

5.3

CVSS4.0

CVE-2026-7680 - jsbroks COCO Annotator Data Endpoint datasets.py path traversal

A weakness has been identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file backend/webserver/api/datasets.py of the component Data Endpoint. Executing a manipulation of the argument folder can lead to path traversal. The attack can be launched remotely. The e…

📅 Published: May 3, 2026, 4:30 a.m. 🔄 Last Modified: May 3, 2026, 4:30 a.m.

7.2

CVSS3.1

CVE-2026-5063 - NEX-Forms <= 9.1.11 - Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to, and including, 9.1.11 due to insufficient input sanitization and output escaping. This makes it pos…

📅 Published: May 3, 2026, 4:25 a.m. 🔄 Last Modified: May 3, 2026, 4:25 a.m.
Total resulsts: 347736
Page 2 of 34,774
« previous page » next page
Filters