8.7

CVSS4.0

CVE-2026-3974 - Tenda W3 HTTP exeCommand formexeCommand stack-based overflow

A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be performed from remote. Th…

πŸ“… Published: March 12, 2026, 2:02 a.m. πŸ”„ Last Modified: March 12, 2026, 2:02 a.m.

6.8

CVSS4.0

CVE-2025-15037 -

An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and k…

πŸ“… Published: March 12, 2026, 2 a.m. πŸ”„ Last Modified: March 12, 2026, 2 a.m.

6.6

CVSS4.0

CVE-2025-59388 - Hyper Data Protector

A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later

πŸ“… Published: March 12, 2026, 1:41 a.m. πŸ”„ Last Modified: March 12, 2026, 1:41 a.m.

4.3

CVSS3.1

CVE-2026-1182 - Improper Removal of Sensitive Information Before Storage or Transfer in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential issue title created in public projects under certain circumstances.

πŸ“… Published: March 12, 2026, 1:33 a.m. πŸ”„ Last Modified: March 12, 2026, 1:33 a.m.

8.7

CVSS4.0

CVE-2026-3973 - Tenda W3 POST Parameter setAutoPing formSetAutoPing stack-based overflow

A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component POST Parameter Handler. This manipulation of the argument ping1/ping2 causes stack-based buffer overflow. The attack is possible to be carried out rem…

πŸ“… Published: March 12, 2026, 1:32 a.m. πŸ”„ Last Modified: March 12, 2026, 1:32 a.m.

8.7

CVSS4.0

CVE-2026-3972 - Tenda W3 HTTP setcfm formSetCfm stack-based overflow

A vulnerability was found in Tenda W3 1.0.0.3(2204). Affected by this issue is the function formSetCfm of the file /goform/setcfm of the component HTTP Handler. The manipulation of the argument funcpara1 results in stack-based buffer overflow. The attack can only be performed from the local network…

πŸ“… Published: March 12, 2026, 1:32 a.m. πŸ”„ Last Modified: March 12, 2026, 1:32 a.m.

8.7

CVSS4.0

CVE-2026-3971 - Tenda i3 wifiSSIDset formwrlSSIDset stack-based overflow

A vulnerability has been found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the argument index/GO leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has bee…

πŸ“… Published: March 12, 2026, 1:02 a.m. πŸ”„ Last Modified: March 12, 2026, 1:02 a.m.

8.7

CVSS4.0

CVE-2026-3970 - Tenda i3 wifiSSIDget formwrlSSIDget stack-based overflow

A flaw has been found in Tenda i3 1.0.0.6(2204). Affected is the function formwrlSSIDget of the file /goform/wifiSSIDget. Executing a manipulation of the argument index can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

πŸ“… Published: March 12, 2026, 1:02 a.m. πŸ”„ Last Modified: March 12, 2026, 1:02 a.m.

0.0

CVE-2023-43010 -

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

πŸ“… Published: March 12, 2026, 12:52 a.m. πŸ”„ Last Modified: March 12, 2026, 12:52 a.m.

6.9

CVSS4.0

CVE-2026-3969 - FeMiner wms Basic Organizational Structure depart_add_bg.php sql injection

A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basic/depart/depart_add_bg.php of the component Basic Organizational Structure Module. Performing a manipulation of the argument Name results in sql injection. The attack may be initi…

πŸ“… Published: March 12, 2026, 12:32 a.m. πŸ”„ Last Modified: March 12, 2026, 12:32 a.m.
Total resulsts: 337524
Page 2 of 33,753
Β« previous page Β» next page
Filters