5.3

CVSS4.0

CVE-2026-7696 - Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform uploadH5Files unres…

A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remo…

📅 Published: May 3, 2026, 12:30 p.m. 🔄 Last Modified: May 3, 2026, 12:30 p.m.

6.9

CVSS4.0

CVE-2026-7695 - Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform elecMaxMinAvgValue …

A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be init…

📅 Published: May 3, 2026, 12:15 p.m. 🔄 Last Modified: May 3, 2026, 12:15 p.m.

6.9

CVSS4.0

CVE-2026-7694 - Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue …

A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impacted element is an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. Executing a manipulation of the argument fCircuitids can lead to sql injection. The attac…

📅 Published: May 3, 2026, 11:45 a.m. 🔄 Last Modified: May 3, 2026, 11:45 a.m.

5.3

CVSS4.0

CVE-2026-7692 - Wavlink WL-WN570HA1 adm.cgi ping_ddns command injection

A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS results in command injection. The attack can be initiated remotely. The exploit is now public and may …

📅 Published: May 3, 2026, 11 a.m. 🔄 Last Modified: May 3, 2026, 11 a.m.

5.3

CVSS4.0

CVE-2026-7691 - Wavlink WL-WN570HA1 adm.cgi set_sys_cmd command injection

A security vulnerability has been detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. Impacted is the function set_sys_cmd of the file /cgi-bin/adm.cgi. Such manipulation of the argument command leads to command injection. It is possible to launch the attack remotely. The exploit has been disclose…

📅 Published: May 3, 2026, 10:15 a.m. 🔄 Last Modified: May 3, 2026, 10:15 a.m.

5.3

CVSS4.0

CVE-2026-7690 - Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection

A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit has been made availab…

📅 Published: May 3, 2026, 9:45 a.m. 🔄 Last Modified: May 3, 2026, 9:45 a.m.

6.3

CVSS4.0

CVE-2026-7689 - Dolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verification

A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib.php of the component Online Signature Module. The manipulation results in improper verification of cryptographic signature. The at…

📅 Published: May 3, 2026, 9:30 a.m. 🔄 Last Modified: May 3, 2026, 9:30 a.m.

2.3

CVSS4.0

CVE-2026-7688 - Dolibarr ERP CRM Shipments API Endpoint expedition.class.php _checkValForAPI sql injection

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file htdocs/expedition/class/expedition.class.php of the component Shipments API Endpoint. The manipulation of the argument fields leads to sql injection. The attack is possible to be c…

📅 Published: May 3, 2026, 9:15 a.m. 🔄 Last Modified: May 3, 2026, 9:15 a.m.

5.3

CVSS4.0

CVE-2026-7687 - langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injecti…

A vulnerability was determined in langflow-ai langflow up to 1.8.4. Affected by this issue is the function CodeParser.parse_callable_details of the file src/lfx/src/lfx/custom/code_parser/code_parser.py of the component Full Builtins Module Handler. Executing a manipulation can lead to command inje…

📅 Published: May 3, 2026, 8:45 a.m. 🔄 Last Modified: May 3, 2026, 8:45 a.m.

6.9

CVSS4.0

CVE-2026-7686 - eyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access control

A vulnerability was found in eyeo Adblock Plus up to 4.36.2 on Chrome. Affected by this vulnerability is the function postMessage of the file premium.preload.js of the component Legacy Premium Activation. Performing a manipulation results in improper access controls. Remote exploitation of the atta…

📅 Published: May 3, 2026, 7:30 a.m. 🔄 Last Modified: May 3, 2026, 7:30 a.m.
Total resulsts: 347744
Page 2 of 34,775
« previous page » next page
Filters