5.1

CVSS4.0

CVE-2026-32844 - XinLiangCoder / php_api_doc Reflected XSS via list_method.php

XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.php that allows remote attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious code through the f parameter. Attackers can craft a malicious URL wit…

πŸ“… Published: March 20, 2026, 5:26 p.m. πŸ”„ Last Modified: April 14, 2026, 4:43 p.m.

8.7

CVSS4.0

CVE-2026-4492 - Tenda A18 Pro formSetQosBand set_qosMib_list stack-based overflow

A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has …

πŸ“… Published: March 20, 2026, 5:02 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

8.7

CVSS4.0

CVE-2026-4491 - Tenda A18 Pro SetIpMacBind fromSetIpMacBind stack-based overflow

A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed to the public and…

πŸ“… Published: March 20, 2026, 4:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

8.7

CVSS4.0

CVE-2026-4490 - Tenda A18 Pro openSchedWifi setSchedWifi stack-based overflow

A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

πŸ“… Published: March 20, 2026, 4:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

7.7

CVSS4.0

CVE-2025-15608 - Buffer Overflow in Network Probe Handling Function of TP-Link Archer AX53

This vulnerability in AX53 v1 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through …

πŸ“… Published: March 20, 2026, 4:31 p.m. πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

7.3

CVSS4.0

CVE-2025-15607 - Authenticated Command Injection in mcsd Service of TP-Link Archer AX53

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary command…

πŸ“… Published: March 20, 2026, 4:31 p.m. πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

2.7

CVSS4.0

CVE-2025-59383 - Media Streaming Add-on

A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later

πŸ“… Published: March 20, 2026, 4:22 p.m. πŸ”„ Last Modified: April 14, 2026, 4:43 p.m.

0.9

CVSS4.0

CVE-2025-62843 - QuRouter

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulne…

πŸ“… Published: March 20, 2026, 4:22 p.m. πŸ”„ Last Modified: April 14, 2026, 4:43 p.m.

4

CVSS4.0

CVE-2025-62844 - QuRouter

A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: April 14, 2026, 4:43 p.m.

5.6

CVSS4.0

CVE-2025-62845 - QuRouter

An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to cause unexpected behavior. We have already fixed the vulnerability in the following versi…

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.
Total resulsts: 348618
Page 958 of 34,862
Β« previous page Β» next page
Filters