5.1
CVE-2026-4044 - projectsend Delete import-orphans.php realpath path traversal
A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument files[] results in path traversal. Remote exploitation of the attack is possible. The exploit is nowβ¦
8.7
CVE-2026-4043 - Tenda i12 wifiSSIDget formwrlSSIDget stack-based overflow
A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDget of the file /goform/wifiSSIDget. Such manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosβ¦
8.8
CVE-2026-21668 -
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
10
CVE-2026-21669 -
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
9.1
CVE-2026-21671 -
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
7.7
CVE-2026-21670 -
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
10
CVE-2026-21666 -
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
10
CVE-2026-21667 -
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
8.7
CVE-2026-4042 - Tenda i12 WifiMacFilterGet formWifiMacFilterGet stack-based overflow
A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made avaiβ¦
8.7
CVE-2026-4041 - Tenda i12 exeCommand vos_strcpy stack-based overflow
A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and β¦