8.7

CVSS4.0

CVE-2026-32669 -

Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.

📅 Published: March 27, 2026, 5:24 a.m. 🔄 Last Modified: March 27, 2026, 5:24 a.m.

8.6

CVSS4.0

CVE-2026-27650 -

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.

📅 Published: March 27, 2026, 5:24 a.m. 🔄 Last Modified: March 27, 2026, 5:24 a.m.

9.8

CVSS3.1

CVE-2026-22738 - SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression ke…

📅 Published: March 27, 2026, 5:21 a.m. 🔄 Last Modified: March 27, 2026, 5:21 a.m.

5.1

CVSS4.0

CVE-2026-33559 -

WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user acces…

📅 Published: March 27, 2026, 4:56 a.m. 🔄 Last Modified: March 27, 2026, 4:56 a.m.

5.9

CVSS3.1

CVE-2026-34353 -

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

📅 Published: March 27, 2026, 4:55 a.m. 🔄 Last Modified: March 27, 2026, 5:03 a.m.

6.5

CVSS3.1

CVE-2026-3098 - Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll

The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the …

📅 Published: March 27, 2026, 3:37 a.m. 🔄 Last Modified: March 27, 2026, 3:37 a.m.

6.9

CVSS4.0

CVE-2026-4910 - Shenzhen Ruiming Technology Streamax Crocus Endpoint RemoteFormat.do sql injection

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus bis 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such manipulation of the argument State leads to sql injection. It is possible to launch the attack remotely.…

📅 Published: March 27, 2026, 3:01 a.m. 🔄 Last Modified: March 27, 2026, 4:16 a.m.

6.9

CVSS4.0

CVE-2026-4908 - code-projects Simple Laundry System Parameter modstaffinfo.php sql injection

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in sql injection. The attack may be performed from remote. The exploit h…

📅 Published: March 27, 2026, 2:25 a.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

5.3

CVSS4.0

CVE-2026-4907 - Page-Replica Page Replica Endpoint sitemap sitemap.fetch server-side request forgery

A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function sitemap.fetch of the file /sitemap of the component Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is pos…

📅 Published: March 27, 2026, 1:33 a.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

8.7

CVSS4.0

CVE-2026-4906 - Tenda AC5 POST Request WizardHandle decodePwd stack-based overflow

A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remo…

📅 Published: March 27, 2026, 12:53 a.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.
Total resulsts: 340774
Page 3 of 34,078
« previous page » next page
Filters