8.7

CVSS4.0

CVE-2026-6013 - D-Link DIR-513 POST Request formSetRoute buffer overflow

A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit…

📅 Published: April 10, 2026, 4:15 a.m. 🔄 Last Modified: April 10, 2026, 3:35 p.m.

8.7

CVSS4.0

CVE-2026-6012 - D-Link DIR-513 POST Request formSetPassword buffer overflow

A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotel…

📅 Published: April 10, 2026, 4 a.m. 🔄 Last Modified: April 10, 2026, 3:54 p.m.

6.3

CVSS4.0

CVE-2026-6011 - OpenClaw assertPublicHostname web-fetch.ts server-side request forgery

A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fetch.ts of the component assertPublicHostname Handler. Executing a manipulation can lead to server-side request forgery. The attack can be executed remo…

📅 Published: April 10, 2026, 3:45 a.m. 🔄 Last Modified: April 10, 2026, 1:41 p.m.

6.4

CVSS3.1

CVE-2026-2305 - AddFunc Head & Footer Code <= 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Cu…

The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `aFhfc_footer_code` post meta values in all versions up to, and including, 2.3. This is due to the plugin outputting these meta values without any sanit…

📅 Published: April 10, 2026, 3:35 a.m. 🔄 Last Modified: April 10, 2026, 5:03 p.m.

5.3

CVSS4.0

CVE-2026-6010 - CodeAstro Online Classroom takeassessment2.php sql injection

A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/takeassessment2.php?exid=14. Performing a manipulation of the argument Q1 results in sql injection. Remote exploitation of the attack …

📅 Published: April 10, 2026, 3:30 a.m. 🔄 Last Modified: April 10, 2026, 3:30 a.m.

2.3

CVSS4.0

CVE-2026-5188 - Integer underflow in X.509 SAN parsing in wolfSSL

An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry length larger than the enclosing sequence, causing the internal length counter to wrap during parsing. This results in incorrect…

📅 Published: April 10, 2026, 3:24 a.m. 🔄 Last Modified: April 10, 2026, 3:24 a.m.

5.3

CVSS4.0

CVE-2026-6007 - itsourcecode Construction Management System del.php sql injection

A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

📅 Published: April 10, 2026, 3:15 a.m. 🔄 Last Modified: April 10, 2026, 3:15 a.m.

8.7

CVSS4.0

CVE-2026-5500 - Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication B…

wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac field from 16 bytes to 1 byte, reducing the tag check from 2⁻¹²⁸ to 2⁻⁸.

📅 Published: April 10, 2026, 3:10 a.m. 🔄 Last Modified: April 10, 2026, 3:10 a.m.

8.6

CVSS4.0

CVE-2026-5501 - Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificat…

wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by a trusted root. An attacker who obtains any leaf …

📅 Published: April 10, 2026, 3:07 a.m. 🔄 Last Modified: April 10, 2026, 3:07 a.m.

7.6

CVSS4.0

CVE-2026-5466 - wc_VerifyEccsiHash missing sanity check

wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no check that they lie in `[1, q-1]`. A crafted forged signature could verify against any message for any identity, using only publicly-known constants.

📅 Published: April 10, 2026, 3 a.m. 🔄 Last Modified: April 10, 2026, 3 a.m.
Total resulsts: 343923
Page 21 of 34,393
« previous page » next page
Filters