8.7

CVSS4.0

CVE-2025-11500 - Credentials exposure in tinycontrol devices

Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off (which is a default setting), an unauthenticated attacker on …

📅 Published: March 16, 2026, 9:26 a.m. 🔄 Last Modified: March 30, 2026, 8 a.m.

8.6

CVSS4.0

CVE-2025-15587 - Credentials exposure in tinycontrol devices

Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an administrator's password by directly accessing a specific resource inaccessible via a graphical interface. This issue has been fixed in firmware versions: 1.36 (for tcPDU), 1.67 (for L…

📅 Published: March 16, 2026, 9:26 a.m. 🔄 Last Modified: March 30, 2026, 8 a.m.

6.9

CVSS4.0

CVE-2026-4231 - vanna-ai vanna Endpoint __init__.py run_sql server-side request forgery

A vulnerability was found in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function update_sql/run_sql of the file src/vanna/legacy/flask/__init__.py of the component Endpoint. Performing a manipulation results in server-side request forgery. The attack may be initiated remotely…

📅 Published: March 16, 2026, 9:02 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

5.3

CVSS4.0

CVE-2026-4230 - vanna-ai vanna Endpoint __init__.py update_sql sql injection

A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/legacy/flask/__init__.py of the component Endpoint. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and…

📅 Published: March 16, 2026, 8:32 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.9

CVSS4.0

CVE-2026-4229 - vanna-ai vanna bigquery_vector.py remove_training_data sql injection

A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vector.py. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used…

📅 Published: March 16, 2026, 8:32 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

5.3

CVSS4.0

CVE-2026-4228 - LB-LINK BL-WR9000 set_wifi sub_458754 command injection

A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about th…

📅 Published: March 16, 2026, 8:02 a.m. 🔄 Last Modified: March 24, 2026, 10:45 a.m.

8.7

CVSS4.0

CVE-2026-4227 - LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow

A security vulnerability has been detected in LB-LINK BL-WR9000 2.4.9. The impacted element is the function sub_44D844 of the file /goform/get_hidessid_cfg. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be …

📅 Published: March 16, 2026, 8:02 a.m. 🔄 Last Modified: March 24, 2026, 10:45 a.m.

8.7

CVSS4.0

CVE-2026-4226 - LB-LINK BL-WR9000 get_virtual_cfg sub_44E8D0 stack-based overflow

A weakness has been identified in LB-LINK BL-WR9000 2.4.9. The affected element is the function sub_44E8D0 of the file /goform/get_virtual_cfg. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the publi…

📅 Published: March 16, 2026, 7:32 a.m. 🔄 Last Modified: March 24, 2026, 10:45 a.m.

4.8

CVSS4.0

CVE-2026-4225 - CMS Made Simple User Management listusers.php cross site scripting

A security flaw has been discovered in CMS Made Simple up to 2.2.21. Impacted is an unknown function of the file admin/listusers.php of the component User Management Module. Performing a manipulation of the argument Message results in cross site scripting. The attack is possible to be carried out r…

📅 Published: March 16, 2026, 7:32 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

8.4

CVSS4.0

CVE-2026-4255 - DLL Injection Privilege Escalation

A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to escalate privileges via DLL side-loading. The application loads certain dynamic-link library (DLL) dependencies using the default Windows search order, which includes directories…

📅 Published: March 16, 2026, 7:14 a.m. 🔄 Last Modified: March 24, 2026, 10:45 a.m.
Total resulsts: 349182
Page 1101 of 34,919
« previous page » next page
Filters