8.7

CVSS4.0

CVE-2026-4167 - Belkin F9K1122 formReboot stack-based overflow

A vulnerability was determined in Belkin F9K1122 1.00.33. This affects the function formReboot of the file /goform/formReboot. This manipulation of the argument webpage causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utili…

📅 Published: March 15, 2026, 5:32 a.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

5.1

CVSS4.0

CVE-2026-4166 - Wavlink WL-NU516U1 login.cgi sub_404F68 cross site scripting

A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could…

📅 Published: March 15, 2026, 5:32 a.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

4.8

CVSS4.0

CVE-2026-4165 - Worksuite HR, CRM and Project Management create cross site scripting

A vulnerability has been found in Worksuite HR, CRM and Project Management up to 5.5.25. The affected element is an unknown function of the file /account/orders/create. The manipulation of the argument Client Note leads to cross site scripting. The attack can be initiated remotely. The exploit has …

📅 Published: March 15, 2026, 5:02 a.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

9.3

CVSS4.0

CVE-2026-4164 - Wavlink WL-WN578W2 POST Request wireless.cgi GuestWifi command injection

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Executing a manipulation can lead to command injection. It is possible to launch the attack remotely. The exploit h…

📅 Published: March 15, 2026, 3:02 a.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

5.3

CVSS3.1

CVE-2026-2233 - User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration…

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it p…

📅 Published: March 15, 2026, 2:19 a.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

7.5

CVSS3.1

CVE-2026-1947 - NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated…

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled key. This makes it possible for unauthenticated at…

📅 Published: March 15, 2026, 1:19 a.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

4.3

CVSS3.1

CVE-2026-1883 - Wicked Folders <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrar…

The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validation on a user controlled key. This makes it possib…

📅 Published: March 15, 2026, 1:19 a.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

9.3

CVSS4.0

CVE-2026-4163 - Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection

A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The exploit i…

📅 Published: March 14, 2026, 10:32 p.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

6.1

CVSS3.1

CVE-2026-4179 - stm32: usb: Infinite while loop in Interrupt Handler

Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.

📅 Published: March 14, 2026, 9:51 p.m. 🔄 Last Modified: April 3, 2026, 9:39 a.m.

5.3

CVSS4.0

CVE-2026-32774 - Vulnogram - Stored Cross-Site Scripting via Comment Hypertext

Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScript in victims' browsers.

📅 Published: March 14, 2026, 9:44 p.m. 🔄 Last Modified: March 23, 2026, 1:39 p.m.
Total resulsts: 347827
Page 980 of 34,783
« previous page » next page
Filters