5.1

CVSS4.0

CVE-2023-54358 - WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at th…

πŸ“… Published: April 9, 2026, 8:54 p.m. πŸ”„ Last Modified: April 10, 2026, 6:10 p.m.

8.7

CVSS4.0

CVE-2026-5979 - D-Link DIR-605L POST Request formVirtualServ buffer overflow

A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely…

πŸ“… Published: April 9, 2026, 8:45 p.m. πŸ”„ Last Modified: April 10, 2026, 6:08 p.m.

9.3

CVSS4.0

CVE-2026-5978 - Totolink A7100RU CGI cstecgi.cgi setWiFiAclRules os command injection

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument mode leads to os command injection. The attack can be initiated remotely. The…

πŸ“… Published: April 9, 2026, 8:30 p.m. πŸ”„ Last Modified: April 9, 2026, 8:30 p.m.

8.1

CVSS3.1

CVE-2026-40093 - nimiq-blockchain is missing a wall-clock upper bound on block timestamps

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for non-skip blocks and timestamp == parent.timestamp + MIN_PRODUCER_TIMEOUT for skip blocks, but there is no visible uppe…

πŸ“… Published: April 9, 2026, 8:29 p.m. πŸ”„ Last Modified: April 10, 2026, 9:29 a.m.

9.3

CVSS4.0

CVE-2026-5977 - Totolink A7100RU CGI cstecgi.cgi setWiFiBasicCfg os command injection

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wifiOff can lead to os command injection. It is possible to launch the attack re…

πŸ“… Published: April 9, 2026, 8:15 p.m. πŸ”„ Last Modified: April 9, 2026, 8:15 p.m.

6.3

CVSS4.0

CVE-2026-5447 - Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier

Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when converting an X.509 certificate internally due to incorrect size handling of the AuthorityKeyIdentifier extension.

πŸ“… Published: April 9, 2026, 8:13 p.m. πŸ”„ Last Modified: April 10, 2026, 6:07 p.m.

8.6

CVSS3.1

CVE-2026-4436 - GPL Odorizers GPL750 Missing Authentication for Critical Function

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

πŸ“… Published: April 9, 2026, 8:04 p.m. πŸ”„ Last Modified: April 9, 2026, 8:04 p.m.

9.3

CVSS4.0

CVE-2026-5976 - Totolink A7100RU CGI cstecgi.cgi setStorageCfg os command injection

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sambaEnabled results in os command injection. It is possible to initiate the…

πŸ“… Published: April 9, 2026, 8 p.m. πŸ”„ Last Modified: April 9, 2026, 8 p.m.

9.3

CVSS4.0

CVE-2025-13926 - Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision

An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.

πŸ“… Published: April 9, 2026, 7:47 p.m. πŸ”„ Last Modified: April 9, 2026, 7:47 p.m.

2.3

CVSS4.0

CVE-2026-5187 - Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL

Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID arc values (out[0] and out[1]), enabling a 2-byte out-of-bounds write when outSz equals 1. Second, multiple callers pas…

πŸ“… Published: April 9, 2026, 7:45 p.m. πŸ”„ Last Modified: April 9, 2026, 7:45 p.m.
Total resulsts: 343923
Page 36 of 34,393
Β« previous page Β» next page
Filters