8.7

CVSS4.0

CVE-2026-6014 - D-Link DIR-513 POST Request formAdvanceSetup buffer overflow

A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. It is possible to initiate the attack remotely. The exploit ha…

📅 Published: April 10, 2026, 4:30 a.m. 🔄 Last Modified: April 10, 2026, 4:30 a.m.

6.8

CVSS4.0

CVE-2026-4482 - Insight Agent Private Key Information Disclosure via Inherited File Permissions

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any loc…

📅 Published: April 10, 2026, 4:22 a.m. 🔄 Last Modified: April 10, 2026, 3:33 p.m.

8.7

CVSS4.0

CVE-2026-6013 - D-Link DIR-513 POST Request formSetRoute buffer overflow

A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit…

📅 Published: April 10, 2026, 4:15 a.m. 🔄 Last Modified: April 10, 2026, 3:35 p.m.

8.7

CVSS4.0

CVE-2026-6012 - D-Link DIR-513 POST Request formSetPassword buffer overflow

A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotel…

📅 Published: April 10, 2026, 4 a.m. 🔄 Last Modified: April 10, 2026, 3:54 p.m.

6.3

CVSS4.0

CVE-2026-6011 - OpenClaw assertPublicHostname web-fetch.ts server-side request forgery

A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fetch.ts of the component assertPublicHostname Handler. Executing a manipulation can lead to server-side request forgery. The attack can be executed remo…

📅 Published: April 10, 2026, 3:45 a.m. 🔄 Last Modified: April 10, 2026, 1:41 p.m.

6.4

CVSS3.1

CVE-2026-2305 - AddFunc Head & Footer Code <= 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Cu…

The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `aFhfc_footer_code` post meta values in all versions up to, and including, 2.3. This is due to the plugin outputting these meta values without any sanit…

📅 Published: April 10, 2026, 3:35 a.m. 🔄 Last Modified: April 10, 2026, 5:03 p.m.

5.3

CVSS4.0

CVE-2026-6010 - CodeAstro Online Classroom takeassessment2.php sql injection

A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/takeassessment2.php?exid=14. Performing a manipulation of the argument Q1 results in sql injection. Remote exploitation of the attack …

📅 Published: April 10, 2026, 3:30 a.m. 🔄 Last Modified: April 10, 2026, 3:30 a.m.

2.3

CVSS4.0

CVE-2026-5188 - Integer underflow in X.509 SAN parsing in wolfSSL

An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry length larger than the enclosing sequence, causing the internal length counter to wrap during parsing. This results in incorrect…

📅 Published: April 10, 2026, 3:24 a.m. 🔄 Last Modified: April 10, 2026, 3:24 a.m.

5.3

CVSS4.0

CVE-2026-6007 - itsourcecode Construction Management System del.php sql injection

A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

📅 Published: April 10, 2026, 3:15 a.m. 🔄 Last Modified: April 10, 2026, 3:15 a.m.

8.7

CVSS4.0

CVE-2026-5500 - Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication B…

wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac field from 16 bytes to 1 byte, reducing the tag check from 2⁻¹²⁸ to 2⁻⁸.

📅 Published: April 10, 2026, 3:10 a.m. 🔄 Last Modified: April 10, 2026, 3:10 a.m.
Total resulsts: 343975
Page 26 of 34,398
« previous page » next page
Filters