8.7

CVSS4.0

CVE-2026-7029 - Tenda F456 addressNat fromaddressNat buffer overflow

A weakness has been identified in Tenda F456 1.0.0.5. The impacted element is the function fromaddressNat of the file /goform/addressNat. Executing a manipulation of the argument menufacturer/Go can lead to buffer overflow. The attack may be performed from remote. The exploit has been made availablโ€ฆ

๐Ÿ“… Published: April 26, 2026, 9 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 9 a.m.

5.1

CVSS4.0

CVE-2026-7028 - CodeAstro Online Job Portal All Jobs delete-jobs.php sql injection

A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carrโ€ฆ

๐Ÿ“… Published: April 26, 2026, 8:45 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 8:45 a.m.

4.8

CVSS4.0

CVE-2026-7027 - D-Link DSL-2740R Wireless Setup Section cross site scripting

A vulnerability was identified in D-Link DSL-2740R EU_01.15. Impacted is an unknown function of the component Wireless Setup Section. Such manipulation of the argument Wireless Network Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and migโ€ฆ

๐Ÿ“… Published: April 26, 2026, 8:15 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 8:15 a.m.

6.8

CVSS4.0

CVE-2026-7026 - D-Link DGS-3420 System Information Settings cross site scripting

A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been puโ€ฆ

๐Ÿ“… Published: April 26, 2026, 7:15 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 7:15 a.m.

6.9

CVSS4.0

CVE-2026-7025 - Typecho Ping Back Service Endpoint Service.php sendPingHandle server-side request forgery

A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php of the component Ping Back Service Endpoint. The manipulation of the argument X-Pingback/link results in server-side request forgery. The attack may bโ€ฆ

๐Ÿ“… Published: April 26, 2026, 7 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 7 a.m.

5.3

CVSS4.0

CVE-2026-7024 - rawchen sims deleteFileServlet Endpoint DeleteFileServlet.java path traversal

A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/servlet/file/DeleteFileServlet.java of the component deleteFileServlet Endpoint. Executing a manipulation of the argument filenaโ€ฆ

๐Ÿ“… Published: April 26, 2026, 6:45 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 6:45 a.m.

5.3

CVSS4.0

CVE-2026-7023 - ByteDance coze-studio databaseTool database_impl.go ExecuteSQL sql injection

A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the component databaseTool. Performing a manipulation results in sql injection. The attack can be initiโ€ฆ

๐Ÿ“… Published: April 26, 2026, 6:30 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 6:30 a.m.

6.9

CVSS4.0

CVE-2026-7022 - SmythOS sre HTTP Header AgentRuntime.class.ts AgentRuntime improper authentication

A security vulnerability has been detected in SmythOS sre up to 0.0.15. Affected is the function AgentRuntime of the file packages/core/src/subsystems/AgentManager/AgentRuntime.class.ts of the component HTTP Header Handler. Such manipulation of the argument X-DEBUG-RUN/X-DEBUG-INJ leads to improperโ€ฆ

๐Ÿ“… Published: April 26, 2026, 5:45 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 5:45 a.m.

5.1

CVSS4.0

CVE-2026-7021 - SmythOS sre Connector Service utils.ts information disclosure

A weakness has been identified in SmythOS sre up to 0.0.15. This impacts an unknown function of the file packages/sdk/src/LLM/utils.ts of the component Connector Service. This manipulation of the argument baseURL causes information disclosure. It is possible to initiate the attack remotely. The expโ€ฆ

๐Ÿ“… Published: April 26, 2026, 5:30 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 5:30 a.m.

6.3

CVSS4.0

CVE-2026-7020 - Ollama Tensor Model Transfer transfer.go digestToPath path traversal

A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. โ€ฆ

๐Ÿ“… Published: April 26, 2026, 4:45 a.m. ๐Ÿ”„ Last Modified: April 26, 2026, 4:45 a.m.
Total resulsts: 346624
Page 6 of 34,663
ยซ previous page ยป next page
Filters