5.3

CVSS4.0

CVE-2026-4203 - D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_portforwardiโ€ฆ

๐Ÿ“… Published: March 16, 2026, 1:02 a.m. ๐Ÿ”„ Last Modified: March 16, 2026, 1:02 a.m.

6.9

CVSS4.0

CVE-2026-4201 - glowxq glowxq-oj SysFileController.java upload unrestricted upload

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of the file business/business-system/src/main/java/com/glowxq/system/admin/controller/SysFileController.java. Executing a manipulation can lead to unrestโ€ฆ

๐Ÿ“… Published: March 16, 2026, 12:32 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 9:55 a.m.

6.9

CVSS4.0

CVE-2026-4200 - glowxq glowxq-oj ProblemCaseController.java uploadTestcaseZipUrl server-side request forgery

A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This affects the function uploadTestcaseZipUrl of the file business/business-oj/src/main/java/com/glowxq/oj/problem/controller/ProblemCaseController.java. Performing a manipulation results in serโ€ฆ

๐Ÿ“… Published: March 16, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 9:55 a.m.

4.8

CVSS4.0

CVE-2026-4199 - bazinga012 mcp_code_executor index.ts installDependencies command injection

A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function installDependencies of the file src/index.ts. Such manipulation leads to command injection. The attack can only be performed from a local environment. The exploit is publicly availableโ€ฆ

๐Ÿ“… Published: March 16, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 9:55 a.m.

0.0

CVE-2025-69902 -

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

๐Ÿ“… Published: March 16, 2026, midnight ๐Ÿ”„ Last Modified: March 17, 2026, 9:55 a.m.

8.8

CVSS3.1

CVE-2025-69784 -

A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an attacker-controlled DLL into highโ€ฆ

๐Ÿ“… Published: March 16, 2026, midnight ๐Ÿ”„ Last Modified: March 17, 2026, 9:55 a.m.

5.4

CVSS3.1

CVE-2025-65734 -

An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows attackers to execute arbitrary code via uploading a crafted SVG file.

๐Ÿ“… Published: March 16, 2026, midnight ๐Ÿ”„ Last Modified: March 17, 2026, 9:55 a.m.

5.4

CVSS3.1

CVE-2025-69693 - FFmpeg: out-of-bounds read in RV60 video decoder

Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 fromโ€ฆ

๐Ÿ“… Published: March 16, 2026, midnight ๐Ÿ”„ Last Modified: March 16, 2026, 9:16 p.m.

6.1

CVSS3.1

CVE-2025-57543 -

Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI when viewed by other users. This could potentially lead to user interface redress attacks or be escalated to XSS in certain contexts.

๐Ÿ“… Published: March 16, 2026, midnight ๐Ÿ”„ Last Modified: March 17, 2026, 9:55 a.m.

9.8

CVSS3.1

CVE-2025-69809 -

A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted packet.

๐Ÿ“… Published: March 16, 2026, midnight ๐Ÿ”„ Last Modified: March 17, 2026, 9:55 a.m.
Total resulsts: 338267
Page 20 of 33,827
ยซ previous page ยป next page
Filters