9.3

CVSS4.0

CVE-2026-5993 - Totolink A7100RU CGI cstecgi.cgi setWiFiGuestCfg os command injection

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wifiOff leads to os command injection. The attack can be executed remotel…

πŸ“… Published: April 10, 2026, 12:15 a.m. πŸ”„ Last Modified: April 13, 2026, 3:02 p.m.

8.7

CVSS4.0

CVE-2026-5992 - Tenda F451 P2pListFilter fromP2pListFilter stack-based overflow

A vulnerability was determined in Tenda F451 1.0.0.7. This affects the function fromP2pListFilter of the file /goform/P2pListFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and …

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 3:02 p.m.

0.0

CVE-2026-31412 - usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks() The `check_command_size_in_blocks()` function calculates the data size in bytes by left shifting `common->data_size_from_cmnd` by the b…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:08 a.m.

0.0

CVE-2026-31262 -

Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the URL parameter

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 12:51 p.m.

0.0

CVE-2026-23780 -

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitr…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 12:51 p.m.

0.0

CVE-2026-36233 -

A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for appropri…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 12:51 p.m.

3.5

CVSS3.1

CVE-2026-33551 - Privilege Escalation via Restricted Application Credentials in OpenStack Keystone

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role m…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 3:02 p.m.

0.0

CVE-2026-36235 -

A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 12:51 p.m.

5.4

CVSS3.1

CVE-2026-40212 -

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 12:51 p.m.

0.0

CVE-2026-36234 -

itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 12:51 p.m.
Total resulsts: 344111
Page 43 of 34,412
Β« previous page Β» next page
Filters