5.3

CVSS4.0

CVE-2026-5103 - Totolink A3300R cstecgi.cgi setUPnPCfg command injection

A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection. The attack is possible to be carried out remotely. The exploit has been made avaiโ€ฆ

๐Ÿ“… Published: March 30, 2026, 1 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

2.1

CVSS4.0

CVE-2025-7741 -

Hardcoded Password Vulnerability have been found in CENTUM.ย Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the PROG user. The default โ€ฆ

๐Ÿ“… Published: March 30, 2026, 12:01 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

5.3

CVSS4.0

CVE-2026-5102 - Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection

A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be execuโ€ฆ

๐Ÿ“… Published: March 30, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

6.1

CVSS3.1

CVE-2026-30565 - Reflected Crossโ€‘Site Scripting via 'limit' Parameter in View Supplier

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script oโ€ฆ

๐Ÿ“… Published: March 30, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

6.1

CVSS3.1

CVE-2026-30564 - Reflected XSS via Unsanitized 'limit' Parameter in SourceCodester Sales and Inventory System 1.0

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script oโ€ฆ

๐Ÿ“… Published: March 30, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

0.0

CVE-2026-30308 -

In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a cโ€ฆ

๐Ÿ“… Published: March 30, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 9:17 p.m.

6.1

CVSS3.1

CVE-2026-30082 - Stored Crossโ€‘Site Scripting in IngEstate Server Software Package List Edit Feature

Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters.

๐Ÿ“… Published: March 30, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

6.1

CVSS3.1

CVE-2026-30566 - Reflected XSS in view_customers.php via 'limit' Parameter

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script โ€ฆ

๐Ÿ“… Published: March 30, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

6.1

CVSS3.1

CVE-2026-30563 - Stored XSS in SourceCodester Sales and Inventory System via Unsanitized Website Field

A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update_details.php file. The application fails to sanitize the "website" parameter provided in a POST request. This allows authenticated attackers to injectโ€ฆ

๐Ÿ“… Published: March 30, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

8.2

CVSS3.1

CVE-2026-29872 -

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHub MCP Agent stores user-supplied API tokens in process-wide environment variables using os.environ without pโ€ฆ

๐Ÿ“… Published: March 30, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 7:16 p.m.
Total resulsts: 341475
Page 38 of 34,148
ยซ previous page ยป next page
Filters