8.7

CVSS4.0

CVE-2026-5036 - Tenda 4G06 Endpoint DhcpListClient fromDhcpListClient stack-based overflow

A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the component Endpoint. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack can be initiated remotely. โ€ฆ

๐Ÿ“… Published: March 29, 2026, 7:45 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

6.9

CVSS4.0

CVE-2026-5035 - code-projects Accounting System Parameter view_work.php sql injection

A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclโ€ฆ

๐Ÿ“… Published: March 29, 2026, 7 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

6.9

CVSS4.0

CVE-2026-5034 - code-projects Accounting System Parameter edit_costumer.php sql injection

A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection. It is possible to initiate the attack remotely. The exโ€ฆ

๐Ÿ“… Published: March 29, 2026, 6 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

6.9

CVSS4.0

CVE-2026-5033 - code-projects Accounting System Parameter view_costumer.php sql injection

A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The manipulation of the argument cos_id results in sql injection. The attack may be performed from remotโ€ฆ

๐Ÿ“… Published: March 29, 2026, 5:15 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

5.3

CVSS4.0

CVE-2026-5031 - BichitroGan ISP Billing Software Endpoint users-view resource injection

A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The manipulation of the argument ID results in improper control of resource identifiers. The attack can be launched remotely.โ€ฆ

๐Ÿ“… Published: March 29, 2026, 4:30 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:36 p.m.

5.3

CVSS4.0

CVE-2026-5030 - Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection

A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be initiated remotely. Thโ€ฆ

๐Ÿ“… Published: March 29, 2026, 3:30 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

8.7

CVSS4.0

CVE-2026-5024 - D-Link DIR-513 formSetEmail stack-based overflow

A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formSetEmail. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made pubโ€ฆ

๐Ÿ“… Published: March 29, 2026, 2:45 a.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8 p.m.

4.8

CVSS4.0

CVE-2026-5023 - DeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injection

A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function getCodebase/getRemoteCodebase/saveCodebase of the file src/tools/codebase.ts of the component RepoMix Command Handler. Such manipulation leads to os cโ€ฆ

๐Ÿ“… Published: March 29, 2026, 2 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:36 p.m.

6.4

CVSS3.1

CVE-2026-2602 - Twentig <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWโ€ฆ

The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level accโ€ฆ

๐Ÿ“… Published: March 29, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:36 p.m.

8.7

CVSS4.0

CVE-2026-5021 - Tenda F453 httpd PPTPUserSetting fromPPTPUserSetting stack-based overflow

A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. This manipulation of the argument delno causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publโ€ฆ

๐Ÿ“… Published: March 29, 2026, 1:15 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.
Total resulsts: 349182
Page 812 of 34,919
ยซ previous page ยป next page
Filters