9.3

CVSS4.0

CVE-2017-20223 - Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference

Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: March 16, 2026, 1:28 a.m.

8.7

CVSS4.0

CVE-2017-20222 - Telesquare SKT LTE Router SDT-CS3B1 Unauthenticated Remote Reboot

Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger device reboot without authentication. Attackers can send POST requests to the lte.cgi endpoint with the Command=Reboot parameter to cause denial of ser…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: March 16, 2026, 1:28 a.m.

5.3

CVSS4.0

CVE-2017-20221 - Telesquare SKT LTE Router SDT-CS3B1 CSRF System Command Execution

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting missing request validation. Attackers can craft malicious web pages that perform administrative actions when v…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: March 16, 2026, 1:28 a.m.

5.3

CVSS4.0

CVE-2026-4204 - D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_myfavor…

📅 Published: March 16, 2026, 1:02 a.m. 🔄 Last Modified: March 16, 2026, 1:02 a.m.

5.3

CVSS4.0

CVE-2026-4203 - D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_portforwardi…

📅 Published: March 16, 2026, 1:02 a.m. 🔄 Last Modified: March 16, 2026, 1:02 a.m.

6.9

CVSS4.0

CVE-2026-4201 - glowxq glowxq-oj SysFileController.java upload unrestricted upload

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of the file business/business-system/src/main/java/com/glowxq/system/admin/controller/SysFileController.java. Executing a manipulation can lead to unrest…

📅 Published: March 16, 2026, 12:32 a.m. 🔄 Last Modified: March 17, 2026, 9:55 a.m.

6.9

CVSS4.0

CVE-2026-4200 - glowxq glowxq-oj ProblemCaseController.java uploadTestcaseZipUrl server-side request forgery

A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This affects the function uploadTestcaseZipUrl of the file business/business-oj/src/main/java/com/glowxq/oj/problem/controller/ProblemCaseController.java. Performing a manipulation results in ser…

📅 Published: March 16, 2026, 12:02 a.m. 🔄 Last Modified: March 17, 2026, 9:55 a.m.

4.8

CVSS4.0

CVE-2026-4199 - bazinga012 mcp_code_executor index.ts installDependencies command injection

A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function installDependencies of the file src/index.ts. Such manipulation leads to command injection. The attack can only be performed from a local environment. The exploit is publicly available…

📅 Published: March 16, 2026, 12:02 a.m. 🔄 Last Modified: March 17, 2026, 9:55 a.m.

0.0

CVE-2025-66687 -

Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files

📅 Published: March 16, 2026, midnight 🔄 Last Modified: March 17, 2026, 9:55 a.m.

5.4

CVSS3.1

CVE-2025-65734 -

An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows attackers to execute arbitrary code via uploading a crafted SVG file.

📅 Published: March 16, 2026, midnight 🔄 Last Modified: March 17, 2026, 9:55 a.m.
Total resulsts: 338322
Page 25 of 33,833
« previous page » next page
Filters