6.9

CVSS4.0

CVE-2015-20113 - RealtyScript 4.0.2 Multiple Cross-Site Request Forgery and Persistent Cross-Site Scripting Vulnerabโ€ฆ

Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malicious scripts. Attackers can craft malicious web pages that execute unauthorized actions when logged-iโ€ฆ

๐Ÿ“… Published: March 15, 2026, 6:34 p.m. ๐Ÿ”„ Last Modified: March 19, 2026, 1:58 p.m.

8.7

CVSS4.0

CVE-2013-20006 - Qool CMS Multiple Persistent Cross-Site Scripting Vulnerabilities

Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being stored and returned to users. Attackers can inject malicious JavaScript code through parameters like 'title', 'name', 'email', 'โ€ฆ

๐Ÿ“… Published: March 15, 2026, 6:34 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 6:34 p.m.

6.9

CVSS4.0

CVE-2013-20005 - Qool CMS 2.0 RC2 Cross-Site Request Forgery via adduser

Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious web pages. Attackers can forge POST requests to the /admin/adduser endpoint with parameters like username, password, emailโ€ฆ

๐Ÿ“… Published: March 15, 2026, 6:34 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 6:34 p.m.

5.3

CVSS4.0

CVE-2026-4185 - GPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflow

A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_def_bits_jpeg of the file src/scene_manager/swf_parse.c of the component MP4Box. The manipulation of the argument szName results in stack-based buffer overflow. It is possible to lโ€ฆ

๐Ÿ“… Published: March 15, 2026, 6:32 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 3:18 p.m.

9.3

CVSS4.0

CVE-2026-4184 - D-Link DIR-816 goahead form2Wl5BasicSetup.cgi stack-based overflow

A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the argument pskValue results in stack-based buffer overflow. The attack is possibleโ€ฆ

๐Ÿ“… Published: March 15, 2026, 5:32 p.m. ๐Ÿ”„ Last Modified: March 19, 2026, 7:20 p.m.

9.3

CVSS4.0

CVE-2026-4183 - D-Link DIR-816 goahead form2WlanBasicSetup.cgi stack-based overflow

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the argument pskValue leads to stack-based buffer overflow. The attack can be executed remotely. The expโ€ฆ

๐Ÿ“… Published: March 15, 2026, 4:32 p.m. ๐Ÿ”„ Last Modified: March 19, 2026, 7:56 p.m.

9.3

CVSS4.0

CVE-2026-4182 - D-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow

A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote exploitation of the attack iโ€ฆ

๐Ÿ“… Published: March 15, 2026, 4:02 p.m. ๐Ÿ”„ Last Modified: March 19, 2026, 7:57 p.m.

9.3

CVSS4.0

CVE-2026-4181 - D-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow

A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack may be launched remโ€ฆ

๐Ÿ“… Published: March 15, 2026, 4:02 p.m. ๐Ÿ”„ Last Modified: March 19, 2026, 7:58 p.m.

7.1

CVSS4.0

CVE-2026-28522 - arduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of Service

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets to cause memory exhaustion on the device, triggering a null pointer dereference and resultingโ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:36 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 8:27 p.m.

8.7

CVSS4.0

CVE-2026-28519 - arduino-TuyaOpen DnsServer Heap-Based Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing execution of arbitrary โ€ฆ

๐Ÿ“… Published: March 15, 2026, 1:36 p.m. ๐Ÿ”„ Last Modified: March 15, 2026, 1:36 p.m.
Total resulsts: 339016
Page 99 of 33,902
ยซ previous page ยป next page
Filters