5.3

CVSS4.0

CVE-2026-4197 - D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function RSS_Get_Update_Stat…

πŸ“… Published: March 15, 2026, 11:32 p.m. πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

5.3

CVSS4.0

CVE-2026-4196 - D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This impacts the function cgi_recovery/…

πŸ“… Published: March 15, 2026, 11:32 p.m. πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

5.3

CVSS4.0

CVE-2026-4195 - D-Link DNS-1550-04 wizard_mgr.cgi command injection

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This affects an unknown function of the file /cg…

πŸ“… Published: March 15, 2026, 11:02 p.m. πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

6.9

CVSS4.0

CVE-2026-4194 - D-Link DNS-1550-04 system_mgr.cgi cgi_set_wto access control

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_…

πŸ“… Published: March 15, 2026, 11:02 p.m. πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

6.9

CVSS4.0

CVE-2026-4193 - D-Link DIR-823G goahead UpdateClientInfo access control

A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetDeviceSettings/GetDMZSettings/GetFirewallSettings/GetGuestNetworkSettings/GetLanWanConflictInfo/GetLocalMacAddress/GetNetworkSettings/GetQoSSettings/Ge…

πŸ“… Published: March 15, 2026, 11:02 p.m. πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

5.3

CVSS4.0

CVE-2026-4192 - AvinashBole quip-mcp-server index.ts setupToolHandlers command injection

A vulnerability has been found in AvinashBole quip-mcp-server 1.0.0. Affected by this vulnerability is the function setupToolHandlers of the file src/index.ts. Such manipulation leads to command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may…

πŸ“… Published: March 15, 2026, 8:32 p.m. πŸ”„ Last Modified: March 16, 2026, 8:09 p.m.

6.9

CVSS4.0

CVE-2026-4191 - JawherKl node-api-postgres Profile Picture index.js path.extname unrestricted upload

A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This manipulation causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been published and may…

πŸ“… Published: March 15, 2026, 8:02 p.m. πŸ”„ Last Modified: March 16, 2026, 8:10 p.m.

6.9

CVSS4.0

CVE-2026-4190 - JawherKl node-api-postgres user.js User.getAll sql injection

A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was cont…

πŸ“… Published: March 15, 2026, 7:32 p.m. πŸ”„ Last Modified: March 16, 2026, 8:12 p.m.

5.1

CVSS4.0

CVE-2026-4189 - phpipam Section edit-result.php sql injection

A weakness has been identified in phpipam up to 1.7.4. The impacted element is an unknown function of the file app/admin/sections/edit-result.php of the component Section Handler. Executing a manipulation of the argument subnetOrdering can lead to sql injection. The attack may be launched remotely.…

πŸ“… Published: March 15, 2026, 7:32 p.m. πŸ”„ Last Modified: March 16, 2026, 8:09 p.m.

8.7

CVSS4.0

CVE-2026-4188 - D-Link DIR-619L boa formSchedule stack-based overflow

A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack may be initiated remotely. Th…

πŸ“… Published: March 15, 2026, 7:32 p.m. πŸ”„ Last Modified: March 15, 2026, 7:32 p.m.
Total resulsts: 338279
Page 23 of 33,828
Β« previous page Β» next page
Filters