5.4

CVSS3.1

CVE-2025-69693 - FFmpeg: out-of-bounds read in RV60 video decoder

Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from…

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:01 p.m.

7.8

CVSS3.1

CVE-2025-69783 - OpenEDR Local Self‑Defense Bypass Leading to Privilege Escalation

A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.g., csrss.exe, edrsvc.exe, edrcon.exe). This allows unauthorized interaction with the OpenEDR kernel driver, granting access to privileged functionality such as…

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2 p.m.

5.4

CVSS3.1

CVE-2025-65734 - Authenticated Arbitrary File Upload in gunet Open eClass v3.11 Enables Remote Code Execution via SVG

An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows attackers to execute arbitrary code via uploading a crafted SVG file.

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 9:01 p.m.

4.8

CVSS4.0

CVE-2026-4198 - hypermodel-labs mcp-server-auto-commit index.ts getGitChanges command injection

A vulnerability was determined in hypermodel-labs mcp-server-auto-commit 1.0.0. Affected by this vulnerability is the function getGitChanges of the file index.ts. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be …

πŸ“… Published: March 15, 2026, 11:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

5.3

CVSS4.0

CVE-2026-4197 - D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function RSS_Get_Update_Stat…

πŸ“… Published: March 15, 2026, 11:32 p.m. πŸ”„ Last Modified: March 23, 2026, 2:01 p.m.

5.3

CVSS4.0

CVE-2026-4196 - D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This impacts the function cgi_recovery/…

πŸ“… Published: March 15, 2026, 11:32 p.m. πŸ”„ Last Modified: March 23, 2026, 2:01 p.m.

5.3

CVSS4.0

CVE-2026-4195 - D-Link DNS-1550-04 wizard_mgr.cgi command injection

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This affects an unknown function of the file /cg…

πŸ“… Published: March 15, 2026, 11:02 p.m. πŸ”„ Last Modified: March 23, 2026, 2:01 p.m.

6.9

CVSS4.0

CVE-2026-4194 - D-Link DNS-1550-04 system_mgr.cgi cgi_set_wto access control

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_…

πŸ“… Published: March 15, 2026, 11:02 p.m. πŸ”„ Last Modified: March 23, 2026, 2:01 p.m.

6.9

CVSS4.0

CVE-2026-4193 - D-Link DIR-823G goahead UpdateClientInfo access control

A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetDeviceSettings/GetDMZSettings/GetFirewallSettings/GetGuestNetworkSettings/GetLanWanConflictInfo/GetLocalMacAddress/GetNetworkSettings/GetQoSSettings/Ge…

πŸ“… Published: March 15, 2026, 11:02 p.m. πŸ”„ Last Modified: April 8, 2026, 8:02 p.m.

5.3

CVSS4.0

CVE-2026-4192 - AvinashBole quip-mcp-server index.ts setupToolHandlers command injection

A vulnerability has been found in AvinashBole quip-mcp-server 1.0.0. Affected by this vulnerability is the function setupToolHandlers of the file src/index.ts. Such manipulation leads to command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may…

πŸ“… Published: March 15, 2026, 8:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.
Total resulsts: 349182
Page 1109 of 34,919
Β« previous page Β» next page
Filters