8.7

CVSS4.0

CVE-2026-7019 - Tenda F456 P2pListFilter fromP2pListFilter buffer overflow

A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly availโ€ฆ

๐Ÿ“… Published: April 26, 2026, 4:30 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 6:41 p.m.

6.3

CVSS4.0

CVE-2026-7018 - Datavane Datavines JWT Token TokenManager.java hard-coded key

A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argโ€ฆ

๐Ÿ“… Published: April 26, 2026, 3:30 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 8:20 p.m.

4.8

CVSS4.0

CVE-2026-7016 - MaxSite CMS ushki Plugin cross site scripting

A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and coulโ€ฆ

๐Ÿ“… Published: April 26, 2026, 3:15 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 6:41 p.m.

7.2

CVSS3.1

CVE-2026-42255 - DNS Amplification via Cyclic Name Server Delegation

Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

๐Ÿ“… Published: April 26, 2026, 2:48 a.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-7015 - MaxSite CMS Guestbook Plugin cross site scripting

A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: April 26, 2026, 2:45 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 6:41 p.m.

4

CVSS3.1

CVE-2026-42254 - Crossโ€‘Zone DNS Poisoning in Hickory DNS Recursor

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

๐Ÿ“… Published: April 26, 2026, 2:38 a.m. ๐Ÿ”„ Last Modified: April 28, 2026, 5:30 a.m.

4.8

CVSS4.0

CVE-2026-7014 - MaxSite CMS down_count Plugin cross site scripting

A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. Upgradinโ€ฆ

๐Ÿ“… Published: April 26, 2026, 2:30 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 6:41 p.m.

4.8

CVSS4.0

CVE-2026-7013 - MaxSite CMS mail_send Plugin cross site scripting

A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated remotely. The exploit hโ€ฆ

๐Ÿ“… Published: April 26, 2026, 2 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 6:41 p.m.

4.8

CVSS4.0

CVE-2026-7012 - MaxSite CMS Redirect Plugin cross site scripting

A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to versiโ€ฆ

๐Ÿ“… Published: April 26, 2026, 1:15 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 6:41 p.m.

4.8

CVSS4.0

CVE-2026-7011 - MaxSite CMS Antispam Plugin plugin_antispam cross site scripting

A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It is possible to launโ€ฆ

๐Ÿ“… Published: April 26, 2026, 12:30 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 6:41 p.m.
Total resulsts: 347056
Page 50 of 34,706
ยซ previous page ยป next page
Filters