9.3

CVSS4.0

CVE-2026-7204 - Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exp…

πŸ“… Published: April 28, 2026, 12:15 a.m. πŸ”„ Last Modified: April 28, 2026, 12:15 a.m.

9.3

CVSS4.0

CVE-2026-7203 - Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be launched remotely. T…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, midnight

5.9

CVSS3.1

CVE-2026-40355 -

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_messa…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 5:13 a.m.

5.9

CVSS3.1

CVE-2026-40356 -

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the proc…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 5:23 a.m.

6.5

CVSS3.1

CVE-2026-41526 -

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to …

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 6:52 a.m.

6.5

CVSS3.1

CVE-2026-41525 -

KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executa…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 7:02 a.m.

0.0

CVE-2026-38949 -

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 4:06 p.m.

0.0

CVE-2025-67223 -

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 2:21 p.m.

0.0

CVE-2025-60889 -

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 3:16 p.m.

5.3

CVSS3.1

CVE-2025-60887 -

An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Classes with pointer-like mechanics under the cista::raw namespace are prone to reference tampering, w…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 3:09 p.m.
Total resulsts: 347742
Page 89 of 34,775
Β« previous page Β» next page
Filters