5.3

CVSS4.0

CVE-2026-3966 - 648540858 wvp-GB28181-pro IP Address ABLMediaNodeServerService.java getDownloadFilePath server-side…

A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the function getDownloadFilePath of the file /src/main/java/com/genersoft/iot/vmp/media/abl/ABLMediaNodeServerService.java of the component IP Address Handler. The manipulation of the a…

πŸ“… Published: March 12, 2026, 12:02 a.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS3.1

CVE-2026-3910 - chromium-browser: Inappropriate implementation in V8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 10:20 p.m.

9.1

CVSS3.1

CVE-2026-25818 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption paramete…

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 7:54 p.m.

8.8

CVSS3.1

CVE-2026-3909 - chromium-browser: Out of bounds write in Skia

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 10:20 p.m.

9.8

CVSS3.1

CVE-2026-26791 -

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 14, 2026, 3:23 a.m.

7.5

CVSS3.1

CVE-2026-25819 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP request that leads to a reboot of the device, provided they have …

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 7:54 p.m.

9.8

CVSS3.1

CVE-2026-26793 -

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 4:02 p.m.

9.8

CVSS3.1

CVE-2026-26795 -

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 14, 2026, 3:30 a.m.

8.8

CVSS3.1

CVE-2026-25817 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, prov…

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 7:54 p.m.

7.5

CVSS3.1

CVE-2025-70245 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 7:53 p.m.
Total resulsts: 338049
Page 54 of 33,805
Β« previous page Β» next page
Filters