8.7

CVSS4.0

CVE-2026-4489 - Tenda A18 Pro fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow

A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be…

πŸ“… Published: March 20, 2026, 4:02 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

8.6

CVSS4.0

CVE-2026-32989 - Precurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file upload

Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests to a profile update endpoint handling file uploads. Attackers can exploit this to upload executable files to web-accessible locations, lead…

πŸ“… Published: March 20, 2026, 3:50 p.m. πŸ”„ Last Modified: April 16, 2026, 2:35 p.m.

5.1

CVSS4.0

CVE-2026-32986 - Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection

Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that…

πŸ“… Published: March 20, 2026, 3:42 p.m. πŸ”„ Last Modified: April 16, 2026, 2:44 p.m.

8.7

CVSS4.0

CVE-2026-4488 - UTT HiPER 1250GW setSysAdm strcpy buffer overflow

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the file /goform/setSysAdm. Such manipulation of the argument GroupName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and migh…

πŸ“… Published: March 20, 2026, 3:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

7

CVSS4.0

CVE-2026-4519 - webbrowser.open() allows leading dashes in URLs

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

πŸ“… Published: March 20, 2026, 3:08 p.m. πŸ”„ Last Modified: April 16, 2026, 2:53 p.m.

9.4

CVSS4.0

CVE-2026-22172 - OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized …

πŸ“… Published: March 20, 2026, 2:48 p.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.

5.3

CVSS4.0

CVE-2026-33312 - Read-only Vikunja users can delete project background images via broken object-level authorization

Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, the `DELETE /api/v1/projects/:project/background` endpoint checks `CanRead` permission instead of `CanUpdate`, allowing any user with read-only access to a project to permanently d…

πŸ“… Published: March 20, 2026, 2:42 p.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.

5.3

CVSS3.1

CVE-2026-29794 - Vikunja has Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers

Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unauthenticated users are able to bypass the application's built-in rate-limits by spoofing the `X-Forwarded-For` or `X-Real-IP` headers due to the rate-limit relying on the value of …

πŸ“… Published: March 20, 2026, 2:39 p.m. πŸ”„ Last Modified: March 25, 2026, 2:29 p.m.

8.7

CVSS4.0

CVE-2026-4487 - UTT HiPER 1200GW websHostFilter strcpy buffer overflow

A vulnerability was determined in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/websHostFilter. This manipulation causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

πŸ“… Published: March 20, 2026, 2:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

8.7

CVSS4.0

CVE-2026-4486 - D-Link DIR-513 Web Service formEasySetPassword stack-based overflow

A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the argument curTime results in stack-based buffer overflow. The attack may be performed from remote. The exploit…

πŸ“… Published: March 20, 2026, 2:02 p.m. πŸ”„ Last Modified: April 7, 2026, 8:09 a.m.
Total resulsts: 349182
Page 1016 of 34,919
Β« previous page Β» next page
Filters