9.3

CVSS4.0

CVE-2017-20223 - Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference

Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: April 14, 2026, 4:57 p.m.

8.7

CVSS4.0

CVE-2017-20222 - Telesquare SKT LTE Router SDT-CS3B1 Unauthenticated Remote Reboot

Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger device reboot without authentication. Attackers can send POST requests to the lte.cgi endpoint with the Command=Reboot parameter to cause denial of ser…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: April 14, 2026, 5 p.m.

5.3

CVSS4.0

CVE-2017-20221 - Telesquare SKT LTE Router SDT-CS3B1 CSRF System Command Execution

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting missing request validation. Attackers can craft malicious web pages that perform administrative actions when v…

📅 Published: March 16, 2026, 1:28 a.m. 🔄 Last Modified: April 14, 2026, 5:29 p.m.

5.3

CVSS4.0

CVE-2026-4204 - D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_myfavor…

📅 Published: March 16, 2026, 1:02 a.m. 🔄 Last Modified: March 23, 2026, 2 p.m.

5.3

CVSS4.0

CVE-2026-4203 - D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_portforwardi…

📅 Published: March 16, 2026, 1:02 a.m. 🔄 Last Modified: March 23, 2026, 2 p.m.

6.9

CVSS4.0

CVE-2026-4201 - glowxq glowxq-oj SysFileController.java upload unrestricted upload

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of the file business/business-system/src/main/java/com/glowxq/system/admin/controller/SysFileController.java. Executing a manipulation can lead to unrest…

📅 Published: March 16, 2026, 12:32 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.9

CVSS4.0

CVE-2026-4200 - glowxq glowxq-oj ProblemCaseController.java uploadTestcaseZipUrl server-side request forgery

A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This affects the function uploadTestcaseZipUrl of the file business/business-oj/src/main/java/com/glowxq/oj/problem/controller/ProblemCaseController.java. Performing a manipulation results in ser…

📅 Published: March 16, 2026, 12:02 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

4.8

CVSS4.0

CVE-2026-4199 - bazinga012 mcp_code_executor index.ts installDependencies command injection

A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function installDependencies of the file src/index.ts. Such manipulation leads to command injection. The attack can only be performed from a local environment. The exploit is publicly available…

📅 Published: March 16, 2026, 12:02 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

8.8

CVSS3.1

CVE-2025-69784 - Local Vulnerable IOCTL Enables DLL Injection for SYSTEM Privilege Escalation

A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an attacker-controlled DLL into high…

📅 Published: March 16, 2026, midnight 🔄 Last Modified: March 23, 2026, 2 p.m.

9.1

CVSS3.1

CVE-2025-69808 - Unauthenticated Out‑of‑Bounds Memory Access in p2r3 Bareiron Leading to Information Disclosure and …

An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denial of Service (DoS) via supplying a crafted packet.

📅 Published: March 16, 2026, midnight 🔄 Last Modified: April 27, 2026, 6:41 p.m.
Total resulsts: 349182
Page 1107 of 34,919
« previous page » next page
Filters