8.7

CVSS4.0

CVE-2026-3970 - Tenda i3 wifiSSIDget formwrlSSIDget stack-based overflow

A flaw has been found in Tenda i3 1.0.0.6(2204). Affected is the function formwrlSSIDget of the file /goform/wifiSSIDget. Executing a manipulation of the argument index can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

📅 Published: March 12, 2026, 1:02 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS3.1

CVE-2023-43010 -

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

📅 Published: March 12, 2026, 12:52 a.m. 🔄 Last Modified: March 13, 2026, 7:53 p.m.

6.9

CVSS4.0

CVE-2026-3969 - FeMiner wms Basic Organizational Structure depart_add_bg.php sql injection

A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basic/depart/depart_add_bg.php of the component Basic Organizational Structure Module. Performing a manipulation of the argument Name results in sql injection. The attack may be initi…

📅 Published: March 12, 2026, 12:32 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

5.3

CVSS4.0

CVE-2026-3968 - AutohomeCorp frostmourne Oracle Nashorn JavaScript ExpressionRule.java scriptEngine.eval code injec…

A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remot…

📅 Published: March 12, 2026, 12:32 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

5.3

CVSS4.0

CVE-2026-3967 - Alfresco Activiti Process Variable Serialization System SerializableType.java createObjectInputStre…

A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization Sys…

📅 Published: March 12, 2026, 12:02 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

5.3

CVSS4.0

CVE-2026-3966 - 648540858 wvp-GB28181-pro IP Address ABLMediaNodeServerService.java getDownloadFilePath server-side…

A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the function getDownloadFilePath of the file /src/main/java/com/genersoft/iot/vmp/media/abl/ABLMediaNodeServerService.java of the component IP Address Handler. The manipulation of the a…

📅 Published: March 12, 2026, 12:02 a.m. 🔄 Last Modified: March 12, 2026, 9:07 p.m.

9.1

CVSS3.1

CVE-2026-25818 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption paramete…

📅 Published: March 12, 2026, midnight 🔄 Last Modified: March 13, 2026, 7:54 p.m.

3.3

CVSS3.1

CVE-2025-70873 - sqlite: SQLite: Information Disclosure via Crafted ZIP File

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

📅 Published: March 12, 2026, midnight 🔄 Last Modified: March 14, 2026, 3:35 a.m.

9.8

CVSS3.1

CVE-2026-26795 -

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

📅 Published: March 12, 2026, midnight 🔄 Last Modified: March 14, 2026, 3:30 a.m.

7.5

CVSS3.1

CVE-2026-25819 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP request that leads to a reboot of the device, provided they have …

📅 Published: March 12, 2026, midnight 🔄 Last Modified: March 13, 2026, 7:54 p.m.
Total resulsts: 338004
Page 49 of 33,801
« previous page » next page
Filters