9.1

CVSS3.1

CVE-2026-34177 - VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the restricted.virtual-machines.lowlevel=block project restriction. A remote attac…

πŸ“… Published: April 9, 2026, 9:15 a.m. πŸ”„ Last Modified: April 9, 2026, 9:15 a.m.

0.0

CVE-2026-34538 - Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)

Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected resource, and with the security model …

πŸ“… Published: April 9, 2026, 9:09 a.m. πŸ”„ Last Modified: April 9, 2026, 9:09 a.m.

9.3

CVSS4.0

CVE-2026-5854 - Totolink A7100RU CGI cstecgi.cgi setWiFiEasyCfg os command injection

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument merge results in os command injection. It is possible to initiate the…

πŸ“… Published: April 9, 2026, 6:45 a.m. πŸ”„ Last Modified: April 9, 2026, 6:45 a.m.

9.3

CVSS4.0

CVE-2026-5853 - Totolink A7100RU CGI cstecgi.cgi setIpv6LanCfg os command injection

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument addrPrefixLen leads to os command injection. The attack …

πŸ“… Published: April 9, 2026, 6:30 a.m. πŸ”„ Last Modified: April 9, 2026, 6:30 a.m.

9.3

CVSS4.0

CVE-2026-5852 - Totolink A7100RU CGI cstecgi.cgi setIptvCfg os command injection

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The e…

πŸ“… Published: April 9, 2026, 6:15 a.m. πŸ”„ Last Modified: April 9, 2026, 6:15 a.m.

9.3

CVSS4.0

CVE-2026-5851 - Totolink A7100RU CGI cstecgi.cgi setUPnPCfg os command injection

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be executed remotely. The exploit…

πŸ“… Published: April 9, 2026, 6 a.m. πŸ”„ Last Modified: April 9, 2026, 6 a.m.

9.3

CVSS4.0

CVE-2026-5850 - Totolink A7100RU CGI cstecgi.cgi setVpnPassCfg os command injection

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible.…

πŸ“… Published: April 9, 2026, 5:45 a.m. πŸ”„ Last Modified: April 9, 2026, 5:45 a.m.

6.9

CVSS4.0

CVE-2026-5849 - Tenda i12 HTTP path traversal

A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

πŸ“… Published: April 9, 2026, 5:30 a.m. πŸ”„ Last Modified: April 9, 2026, 5:30 a.m.

5.1

CVSS4.0

CVE-2026-5848 - jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection

A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data Source Handler. Performing a manipulation of the argument dbUrl results in code injection. The att…

πŸ“… Published: April 9, 2026, 5:15 a.m. πŸ”„ Last Modified: April 9, 2026, 5:15 a.m.

5.3

CVSS4.0

CVE-2026-5847 - code-projects Movie Ticketing System SQL Database Backup File moviedb.sql information disclosure

A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file /db/moviedb.sql of the component SQL Database Backup File Handler. Such manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been dis…

πŸ“… Published: April 9, 2026, 5 a.m. πŸ”„ Last Modified: April 9, 2026, 5 a.m.
Total resulsts: 343448
Page 2 of 34,345
Β« previous page Β» next page
Filters