8.7

CVSS4.0

CVE-2026-6134 - Tenda F451 qossetting fromqossetting stack-based overflow

A security flaw has been discovered in Tenda F451 1.0.0.7_cn_svn7958. This vulnerability affects the function fromqossetting of the file /goform/qossetting. Performing a manipulation of the argument qos results in stack-based buffer overflow. The attack is possible to be carried out remotely. The e…

📅 Published: April 12, 2026, 11 p.m. 🔄 Last Modified: April 15, 2026, 3:26 p.m.

8.7

CVSS4.0

CVE-2026-6133 - Tenda F451 SafeUrlFilter fromSafeUrlFilter stack-based overflow

A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. This affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and mig…

📅 Published: April 12, 2026, 10:45 p.m. 🔄 Last Modified: April 13, 2026, 3:01 p.m.

9.3

CVSS4.0

CVE-2026-6132 - Totolink A7100RU CGI cstecgi.cgi setLedCfg os command injection

A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. Remote exploitation of the attack is possibl…

📅 Published: April 12, 2026, 10:30 p.m. 🔄 Last Modified: April 13, 2026, 5:55 p.m.

9.3

CVSS4.0

CVE-2026-6131 - Totolink A7100RU CGI cstecgi.cgi setTracerouteCfg os command injection

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument command results in os command injection. The attack may be launched rem…

📅 Published: April 12, 2026, 10:15 p.m. 🔄 Last Modified: April 14, 2026, 4:33 p.m.

6.9

CVSS4.0

CVE-2026-6130 - chatboxai chatbox Model Context Protocol Server Management System ipc-stdio-transport.ts StdioClien…

A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server Management System. Executing a manipulation of the argument args/env can lead to os command injectio…

📅 Published: April 12, 2026, 10 p.m. 🔄 Last Modified: April 13, 2026, 3:34 p.m.

6.9

CVSS4.0

CVE-2026-6129 - zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication

A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The pr…

📅 Published: April 12, 2026, 7:45 p.m. 🔄 Last Modified: April 15, 2026, 3:25 p.m.

4

CVSS3.1

CVE-2026-40396 - varnish: Varnish Cache: Denial of Service via workspace overflow during HTTP/1 pipelining

Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread (timeout_linger) and resume traffic before the session is closed (timeout_…

📅 Published: April 12, 2026, 7:23 p.m. 🔄 Last Modified: April 17, 2026, 2:38 p.m.

4

CVSS3.1

CVE-2026-40395 - Varnish: Varnish Enterprise: Denial of Service via workspace overflow

Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and writable…

📅 Published: April 12, 2026, 7:21 p.m. 🔄 Last Modified: April 17, 2026, 2:37 p.m.

4

CVSS3.1

CVE-2026-40394 - Varnish Cache: Varnish Enterprise: Varnish Cache and Varnish Enterprise: Denial of Service via work…

Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repur…

📅 Published: April 12, 2026, 7:17 p.m. 🔄 Last Modified: April 17, 2026, 2:35 p.m.

8.1

CVSS3.1

CVE-2026-40393 - Mesa WebGPU Out-of-bounds Memory Access Vulnerability

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

📅 Published: April 12, 2026, 6:49 p.m. 🔄 Last Modified: April 16, 2026, 4:17 p.m.
Total resulsts: 346298
Page 230 of 34,630
« previous page » next page
Filters