7.5
CVE-2025-50666 - Buffer Overflow in D-Link DI-8003 /web_post.asp Endpoint
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time.
7.5
CVE-2025-50661 - Buffer Overflow in D-Link DIโ8003 /url_rule.asp Endpoint Allows Remote Exploitation
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, en, ips, u, time, act, rpri, and log.
7.5
CVE-2025-50655 - Buffer Overflow in DโLink DIโ8003 /thd_group.asp Endpoint
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
7.5
CVE-2025-50667 - Buffer Overflow in DโLink DIโ8003 WAN Line Detection Endpoint
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.
7.5
CVE-2025-50673 - Buffer Overflow in DโLink DIโ8003 via http_lanport Parameter
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.
7.5
CVE-2025-50657 - Buffer Overflow in DโLink DIโ8003 trace.asp Endpoint
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
7.5
CVE-2025-45057 -
D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
7.5
CVE-2025-50660 - Buffer Overflow in D-Link DIโ8003 /url_member.asp Allows Remote Code Execution
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.
0.0
CVE-2026-31017 - SSRF in ERPNext PDF Rendering Allows ServerโSide Requests
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application aโฆ
5.2
CVE-2026-32591 - Mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attackโฆ