7.3

CVSS4.0

CVE-2025-62846 - QuRouter

An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: April 14, 2026, 4:43 p.m.

2.2

CVSS4.0

CVE-2026-22895 - QuFTP Service

A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versio…

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: April 13, 2026, 2:28 p.m.

8.1

CVSS4.0

CVE-2026-22897 - QuNetSwitch

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: March 26, 2026, 12:20 p.m.

9.3

CVSS4.0

CVE-2026-22898 - QVR Pro

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: April 14, 2026, 4:43 p.m.

6.8

CVSS4.0

CVE-2026-22900 - QuNetSwitch

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: March 26, 2026, 12:20 p.m.

6.3

CVSS4.0

CVE-2026-22901 - QuNetSwitch

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: March 26, 2026, 12:20 p.m.

5.7

CVSS4.0

CVE-2026-22902 - QuNetSwitch

A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

πŸ“… Published: March 20, 2026, 4:21 p.m. πŸ”„ Last Modified: March 26, 2026, 12:20 p.m.

8.7

CVSS4.0

CVE-2026-4489 - Tenda A18 Pro fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow

A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be…

πŸ“… Published: March 20, 2026, 4:02 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

8.6

CVSS4.0

CVE-2026-32989 - Precurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file upload

Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests to a profile update endpoint handling file uploads. Attackers can exploit this to upload executable files to web-accessible locations, lead…

πŸ“… Published: March 20, 2026, 3:50 p.m. πŸ”„ Last Modified: April 16, 2026, 2:35 p.m.

5.1

CVSS4.0

CVE-2026-32986 - Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection

Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that…

πŸ“… Published: March 20, 2026, 3:42 p.m. πŸ”„ Last Modified: April 16, 2026, 2:44 p.m.
Total resulsts: 348618
Page 959 of 34,862
Β« previous page Β» next page
Filters