4.8

CVSS3.1

CVE-2026-1858 - wget2 Improper Certificate Validation

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

πŸ“… Published: April 29, 2026, 8:15 p.m. πŸ”„ Last Modified: April 29, 2026, 8:15 p.m.

6.9

CVSS4.0

CVE-2026-7404 - getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It is possible to initia…

πŸ“… Published: April 29, 2026, 8:15 p.m. πŸ”„ Last Modified: April 29, 2026, 8:15 p.m.

6.9

CVSS4.0

CVE-2026-7403 - geldata gel-mcp server.py fetch_rule path traversal

A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in path traversal. The attack may be performed from remote. The exploit has been released to the public…

πŸ“… Published: April 29, 2026, 8 p.m. πŸ”„ Last Modified: April 29, 2026, 8 p.m.

8.7

CVSS4.0

CVE-2026-34965 - Cockpit CMS Authenticated Remote Code Execution via Collections

Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP …

πŸ“… Published: April 29, 2026, 7:50 p.m. πŸ”„ Last Modified: April 29, 2026, 7:50 p.m.

7.1

CVSS4.0

CVE-2018-25311 - VideoFlow Digital Video Protection DVP 10 Authenticated Directory Traversal 2.10 (X-Prototype-Versi…

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal sequences in the ID parameter. Attackers can submit requests to downloadsys.pl, download_xml.pl, downlo…

πŸ“… Published: April 29, 2026, 7:25 p.m. πŸ”„ Last Modified: April 29, 2026, 7:51 p.m.

5.3

CVSS4.0

CVE-2018-25310 - VideoFlow Digital Video Protection DVP 10 Authenticated Remote Code Execution

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cross-site request forgery flaw in the web management interface. Attackers with valid credentials can le…

πŸ“… Published: April 29, 2026, 7:25 p.m. πŸ”„ Last Modified: April 29, 2026, 7:51 p.m.

9.3

CVSS4.0

CVE-2018-25318 - Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS serv…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: April 29, 2026, 7:51 p.m.

9.3

CVSS4.0

CVE-2018-25317 - Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted a…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: April 29, 2026, 7:51 p.m.

9.3

CVSS4.0

CVE-2018-25316 - Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS se…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: April 29, 2026, 7:51 p.m.

8.6

CVSS4.0

CVE-2018-25315 - Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name

Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with structured exception handler (SEH) overwrite and shellcode to achieve code exe…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: April 29, 2026, 7:24 p.m.
Total resulsts: 347728
Page 54 of 34,773
Β« previous page Β» next page
Filters