5.3

CVSS4.0

CVE-2026-40041 - Pachno 1.0.6 Cross-Site Request Forgery via State-Changing Endpoints

Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in authenticated user context by exploiting missing CSRF protections on state-changing endpoints. Attackers can craft malicious requests targeting login, registration, file upload, mi…

πŸ“… Published: April 13, 2026, 6:10 p.m. πŸ”„ Last Modified: April 13, 2026, 7:16 p.m.

8.7

CVSS4.0

CVE-2026-40040 - Pachno 1.0.6 Unrestricted File Upload Remote Code Execution

Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 scripts to web-accessible directories and execute them…

πŸ“… Published: April 13, 2026, 6:10 p.m. πŸ”„ Last Modified: April 14, 2026, 1:08 p.m.

7.1

CVSS4.0

CVE-2026-40039 - Pachno 1.0.6 Open Redirection via return_to Parameter

Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to values to conduct phishing attacks and steal user credentials.

πŸ“… Published: April 13, 2026, 6:10 p.m. πŸ”„ Last Modified: April 13, 2026, 7:16 p.m.

5.1

CVSS4.0

CVE-2026-40038 - Pachno 1.0.6 Stored Cross-Site Scripting via Multiple Parameters

Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads into POST parameters. Attackers can inject scripts through the value, comment_body, article_content, description, and message parameters …

πŸ“… Published: April 13, 2026, 6:10 p.m. πŸ”„ Last Modified: April 13, 2026, 7:16 p.m.

8.7

CVSS4.0

CVE-2026-6197 - Tenda F456 AdvSetWrlsafeset formWrlsafeset stack-based overflow

A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Executing a manipulation of the argument mit_ssid can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been publishe…

πŸ“… Published: April 13, 2026, 6 p.m. πŸ”„ Last Modified: April 13, 2026, 9:16 p.m.

8.2

CVSS3.1

CVE-2026-32316 - jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow

jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buff…

πŸ“… Published: April 13, 2026, 5:49 p.m. πŸ”„ Last Modified: April 13, 2026, 6:56 p.m.

8.7

CVSS4.0

CVE-2026-6196 - Tenda F456 exeCommand fromexeCommand stack-based overflow

A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeCommand. Performing a manipulation of the argument cmdinput results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and ma…

πŸ“… Published: April 13, 2026, 5:45 p.m. πŸ”„ Last Modified: April 13, 2026, 6:16 p.m.

9.3

CVSS4.0

CVE-2026-6195 - Totolink A7100RU CGI cstecgi.cgi setPasswordCfg os command injection

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be execut…

πŸ“… Published: April 13, 2026, 5:30 p.m. πŸ”„ Last Modified: April 13, 2026, 6:16 p.m.

9.1

CVSS4.0

CVE-2026-6100 - Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under …

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the d…

πŸ“… Published: April 13, 2026, 5:15 p.m. πŸ”„ Last Modified: April 14, 2026, 4:33 p.m.

8.7

CVSS4.0

CVE-2026-6194 - Totolink A3002MU HTTP Request formWlanSetup sub_410188 stack-based overflow

A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of …

πŸ“… Published: April 13, 2026, 5:15 p.m. πŸ”„ Last Modified: April 13, 2026, 6:56 p.m.
Total resulsts: 344718
Page 57 of 34,472
Β« previous page Β» next page
Filters