5.3

CVSS4.0

CVE-2026-7086 - HBAI-Ltd Toonflow-app Storyboard Export replaceUrl.ts updateStoryboardUrl path traversal

A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl of the file replaceUrl.ts of the component Storyboard Export. Such manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The expโ€ฆ

๐Ÿ“… Published: April 27, 2026, 4:15 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 4:15 a.m.

2.3

CVSS4.0

CVE-2026-7085 - HBAI-Ltd Toonflow-app downloadApp Endpoint downloadApp.ts z.url path traversal

A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/about/downloadApp.ts of the component downloadApp Endpoint. This manipulation of the argument url causes path traversal. It is possible to initiate the aโ€ฆ

๐Ÿ“… Published: April 27, 2026, 4 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 4 a.m.

5.3

CVSS4.0

CVE-2026-7084 - HBAI-Ltd Toonflow-app getCodeByLink Endpoint getCodeByLink.ts fetch server-side request forgery

A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeByLink.ts of the component getCodeByLink Endpoint. The manipulation of the argument Link results in server-side request forgery. The attack may be perfoโ€ฆ

๐Ÿ“… Published: April 27, 2026, 3:45 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 3:45 a.m.

5.1

CVSS4.0

CVE-2026-7083 - likeadmin-likeshop likeadmin_php dataTable Admin API DataTableLists.php queryResult sql injection

A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function queryResult of the file server\app\adminapi\lists\tools\DataTableLists.php of the component dataTable Admin API. The manipulation leads to sql injection. The attack is possible to โ€ฆ

๐Ÿ“… Published: April 27, 2026, 3:30 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 3:30 a.m.

8.7

CVSS4.0

CVE-2026-7082 - Tenda F456 httpd WrlExtraSet formWrlExtraSet buffer overflow

A flaw has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Executing a manipulation of the argument Go can lead to buffer overflow. The attack can be executed remotely. The exploit has been publโ€ฆ

๐Ÿ“… Published: April 27, 2026, 3:15 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 3:15 a.m.

8.7

CVSS4.0

CVE-2026-7081 - Tenda F456 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow

A vulnerability was detected in Tenda F456 1.0.0.5. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now publiโ€ฆ

๐Ÿ“… Published: April 27, 2026, 3 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 3 a.m.

8.7

CVSS4.0

CVE-2026-3868 -

An improper handling of the length parameter inconsistency vulnerability has been identified in Moxaโ€™s Secure Router.ย Because of improper validation of length parameters in the HTTPS management interface, an unauthenticated remote attacker could send specially crafted requests that trigger a bufferโ€ฆ

๐Ÿ“… Published: April 27, 2026, 2:56 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 2:56 a.m.

6

CVSS4.0

CVE-2026-3867 -

An improper ownership management vulnerability has been identified in Moxaโ€™s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration file containing the hashed password of the administrative account. Successful exploitation of this vulโ€ฆ

๐Ÿ“… Published: April 27, 2026, 2:54 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 2:54 a.m.

8.7

CVSS4.0

CVE-2026-7080 - Tenda F456 httpd PPTPUserSetting fromPPTPUserSetting buffer overflow

A security vulnerability has been detected in Tenda F456 1.0.0.5. This impacts the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. Such manipulation of the argument delno leads to buffer overflow. The attack may be launched remotely. The exploit has been disโ€ฆ

๐Ÿ“… Published: April 27, 2026, 2:45 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 2:45 a.m.

7

CVSS3.1

CVE-2026-3006 - Race Condition Vulnerability

Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software.

๐Ÿ“… Published: April 27, 2026, 2:35 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 2:35 a.m.
Total resulsts: 346667
Page 2 of 34,667
ยซ previous page ยป next page
Filters