8.7

CVSS4.0

CVE-2026-7548 - Totolink NR1800X cstecgi.cgi sub_41A68C command injection

A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd results in command injection. The attack is possible to be carried out remotely. The exploit is now publicโ€ฆ

๐Ÿ“… Published: May 1, 2026, 2:30 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 2:30 a.m.

9.3

CVSS4.0

CVE-2026-7546 - Totolink NR1800X lighttpd find_host_ip stack-based overflow

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been dโ€ฆ

๐Ÿ“… Published: May 1, 2026, 2:15 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 2:15 a.m.

6.9

CVSS4.0

CVE-2026-7545 - SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injecโ€ฆ

A weakness has been identified in SourceCodester Advanced School Management System 1.0. The affected element is an unknown function of the file commonController.php of the component checkEmail Endpoint. This manipulation causes sql injection. Remote exploitation of the attack is possible. The exploโ€ฆ

๐Ÿ“… Published: May 1, 2026, 1:45 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 1:45 a.m.

9.3

CVSS4.0

CVE-2026-7538 - Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument proto leads to os command injection. The attack may be initiated remotely. The exploiโ€ฆ

๐Ÿ“… Published: May 1, 2026, 1:30 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 1:30 a.m.

6.9

CVSS4.0

CVE-2026-7536 - Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function bsf_sess_add_by_ip_address of the file /nbsf-management/v1/pcfBindings of the component BSF. Executing a manipulation of the argument ipv4Addr can lead to denial of service. The attack can be launched remโ€ฆ

๐Ÿ“… Published: May 1, 2026, 1:15 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 1:15 a.m.

5.3

CVSS4.0

CVE-2026-7535 - Open5GS transfer-update denial of service

A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_update_request in the library /lib/app/ogs-init.c of the file /namf-comm/v1/ue-contexts/{ueContextId}/transfer-update. Performing a manipulation of the argument ueContextId results iโ€ฆ

๐Ÿ“… Published: May 1, 2026, 1 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 1 a.m.

6.9

CVSS4.0

CVE-2026-7519 - Fujian Apex LiveBOS Endpoint UploadImage.do path traversal

A vulnerability has been found in Fujian Apex LiveBOS up to 2.0. Impacted is an unknown function of the file /feed/UploadImage.do of the component Endpoint. Such manipulation of the argument filename leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to theโ€ฆ

๐Ÿ“… Published: May 1, 2026, 12:45 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 12:45 a.m.

5.3

CVSS4.0

CVE-2026-7518 - Open5GS AMF SBI Endpoint sdmsubscription-notify amf_namf_callback_handle_sdm_data_change_notify denโ€ฆ

A flaw has been found in Open5GS up to 2.7.7. This issue affects the function amf_namf_callback_handle_sdm_data_change_notify of the file /namf-callback/v1/{id}/sdmsubscription-notify of the component AMF SBI Endpoint. This manipulation of the argument changeItem.newValue causes denial of service. โ€ฆ

๐Ÿ“… Published: May 1, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 12:30 a.m.

8

CVSS3.1

CVE-2026-43003 -

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 1, 2026, 8:07 a.m.

7.9

CVSS3.1

CVE-2026-43001 -

An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credentialโ€ฆ

๐Ÿ“… Published: May 1, 2026, midnight ๐Ÿ”„ Last Modified: May 1, 2026, 7:53 a.m.
Total resulsts: 347394
Page 2 of 34,740
ยซ previous page ยป next page
Filters