7.1

CVSS4.0

CVE-2026-28522 - arduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of Service

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets to cause memory exhaustion on the device, triggering a null pointer dereference and resultingโ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:36 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 8:27 p.m.

8.7

CVSS4.0

CVE-2026-28519 - arduino-TuyaOpen DnsServer Heap-Based Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing execution of arbitrary โ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:36 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:36 p.m.

7

CVSS4.0

CVE-2026-28521 - arduino-TuyaOpen TuyaIoT Out-of-Bounds Memory Read Information Disclosure

arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP event data to victim devices, causing out-of-bounds memory access that may result in information discโ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:35 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 8:24 p.m.

8.6

CVSS4.0

CVE-2026-28520 - arduino-TuyaOpen WiFiMulti Single-Byte Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can exploit the overflow to execute arbitrary code on the affected embedded device.

๐Ÿ“… Published: March 15, 2026, 1:35 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:35 p.m.

5.1

CVSS4.0

CVE-2016-20032 - ZKTeco ZKAccess Security System 5.3.1 Stored XSS

ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the 'holiday_name' and 'memo' POST parameters. Attackers can submit crafted requests with script code inโ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:35 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:35 p.m.

6.8

CVSS4.0

CVE-2016-20031 - ZKTeco ZKBioSecurity 3.0 Local Authorization Bypass via visLogin.jsp

ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClientIp() method which treats IPv6 loopback address 0:0:0:0:0:0:โ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:35 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:35 p.m.

9.3

CVSS4.0

CVE-2016-20030 - ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerโ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:35 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:35 p.m.

6.9

CVSS4.0

CVE-2016-20029 - ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configurโ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:35 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:35 p.m.

5.3

CVSS4.0

CVE-2016-20028 - ZKTeco ZKBioSecurity 3.0 Cross-Site Request Forgery Superadmin

ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Attackers can craft HTTP requests that add superadmin accounts without validity checks, enabling unauthoโ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:35 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:35 p.m.

5.1

CVSS4.0

CVE-2016-20027 - ZKTeco ZKBioSecurity 3.0 Multiple Reflected XSS Vulnerabilities

ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script code by injecting malicious payloads through unsanitized parameters in multiple scripts. Attackers can craft malicious URLs with XSS payloads in vulnerโ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:35 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:35 p.m.
Total resulsts: 338998
Page 98 of 33,900
ยซ previous page ยป next page
Filters