8.7

CVSS4.0

CVE-2026-32838 - Edimax GS-5008PL <= 1.00.54 Transmits Credentials Over Cleartext HTTP

Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.

πŸ“… Published: March 17, 2026, 9:42 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

5.1

CVSS4.0

CVE-2026-32839 - Edimax GS-5008PL <= 1.00.54 CSRF via Management CGI Endpoints

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and re…

πŸ“… Published: March 17, 2026, 9:42 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

5.1

CVSS4.0

CVE-2026-32840 - Edimax GS-5008PL <= 1.00.54 Stored XSS via Device Name

Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payl…

πŸ“… Published: March 17, 2026, 9:42 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

7.1

CVSS4.0

CVE-2026-32842 - Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext

Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username an…

πŸ“… Published: March 17, 2026, 9:41 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

9.2

CVSS4.0

CVE-2026-32841 - Edimax GS-5008PL <= 1.00.54 Global Authentication State Across All Clients

Edimax GS-5008PL firmware version 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any use…

πŸ“… Published: March 17, 2026, 9:41 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

6.3

CVSS4.0

CVE-2026-4349 - Duende IdentityServer4 Token Renewal Endpoint authorize improper authentication

A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the file /connect/authorize of the component Token Renewal Endpoint. This manipulation of the argument id_token_hint causes improper authentication. It is possible to initiate the at…

πŸ“… Published: March 17, 2026, 9:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

7.5

CVSS3.1

CVE-2026-4645 - github.com/antchfx/xpath: xpath: Denial of Service via crafted Boolean XPath expressions

Duplicate of CVE-2026-32287

πŸ“… Published: March 17, 2026, 8:58 p.m. πŸ”„ Last Modified: March 30, 2026, 8:16 a.m.

6.7

CVSS4.0

CVE-2026-2809 - Endpoint DLP Driver DLL

Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger an integer overflow within the DLL Injector, leading to a Blue-Screen-of-Death (BSOD). Successful …

πŸ“… Published: March 17, 2026, 8:20 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

2

CVSS4.0

CVE-2026-4359 - Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

πŸ“… Published: March 17, 2026, 7:42 p.m. πŸ”„ Last Modified: April 2, 2026, 8:23 p.m.

6.5

CVSS3.1

CVE-2026-25936 - GLPI Vulnerable to Authenticated SQL Injection

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

πŸ“… Published: March 17, 2026, 7:41 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.
Total resulsts: 349182
Page 1081 of 34,919
Β« previous page Β» next page
Filters