8.7

CVSS4.0

CVE-2026-3978 - D-Link DIR-513 formEasySetupWizard3 stack-based overflow

A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formEasySetupWizard3. The manipulation of the argument wan_connected results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be…

📅 Published: March 12, 2026, 3:32 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

5.3

CVSS4.0

CVE-2026-3977 - projectsend AJAX Endpoints authorization

A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation leads to missing authorization. The attack can be initiated remotely. The identifier of the patch is 35dfd6f08f7d517709c77ee73e5736714…

📅 Published: March 12, 2026, 3:02 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

8.7

CVSS4.0

CVE-2026-3976 - Tenda W3 POST Parameter WifiMacFilterSet formWifiMacFilterSet stack-based overflow

A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch t…

📅 Published: March 12, 2026, 2:32 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

8.7

CVSS4.0

CVE-2026-3975 - Tenda W3 POST Parameter WifiMacFilterGet formWifiMacFilterGet stack-based overflow

A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation of the argument wl_radio results in stack-based buffer overflow. It is possible…

📅 Published: March 12, 2026, 2:32 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

4.3

CVSS3.1

CVE-2026-3226 - LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notifi…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification triggering due to missing capability checks on all 10 functions in the SendEmailAjax class in all versions up to, and including, 4.3.2.8. The AbstractAjax::catch_lp_ajax() dispatcher verifies…

📅 Published: March 12, 2026, 2:22 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

7.5

CVSS3.1

CVE-2026-3657 - My Sticky Bar <= 2.8.6 - Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action

The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action in all versions up to, and including, 2.8.6. This is due to the handler using attacker-controlled POST parameter names directly as SQL column identifiers in `$wpdb->insert()`. Wh…

📅 Published: March 12, 2026, 2:22 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

6.9

CVSS4.0

CVE-2025-15038 -

An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL  request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "…

📅 Published: March 12, 2026, 2:03 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

5.4

CVSS4.0

CVE-2026-1878 -

An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitima…

📅 Published: March 12, 2026, 2:02 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

8.7

CVSS4.0

CVE-2026-3974 - Tenda W3 HTTP exeCommand formexeCommand stack-based overflow

A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be performed from remote. Th…

📅 Published: March 12, 2026, 2:02 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

6.8

CVSS4.0

CVE-2025-15037 -

An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and k…

📅 Published: March 12, 2026, 2 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.
Total resulsts: 337999
Page 47 of 33,800
« previous page » next page
Filters