9.8

CVSS3.1

CVE-2025-15578 - Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely

Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.

๐Ÿ“… Published: Feb. 16, 2026, 9:18 p.m. ๐Ÿ”„ Last Modified: March 10, 2026, 3:07 p.m.

7.5

CVSS3.1

CVE-2026-2474 - Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in tโ€ฆ

Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supplied, the expression length + 1u causes an intโ€ฆ

๐Ÿ“… Published: Feb. 16, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6 p.m.

0.0

CVE-2026-2598 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: Feb. 16, 2026, 8:33 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 10:19 p.m.

8.8

CVSS3.1

CVE-2026-2001 - WowRevenue <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installโ€ฆ

The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin' function in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with subscriber-level access andโ€ฆ

๐Ÿ“… Published: Feb. 16, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 6:30 p.m.

8.6

CVSS4.0

CVE-2026-2567 - Wavlink WL-NU516U1 nas.cgi sub_401218 stack-based overflow

A vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the file /cgi-bin/nas.cgi. Performing a manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now publicโ€ฆ

๐Ÿ“… Published: Feb. 16, 2026, 5:32 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 7 p.m.

5.3

CVSS4.0

CVE-2019-25395 - Smoothwall Express 3.1 'preferences.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloadsโ€ฆ

๐Ÿ“… Published: Feb. 16, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.3

CVSS4.0

CVE-2019-25394 - Smoothwall Express 3.1 'modem.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted payloads in parameters like INIT, HANGUP, SPEAKER_ON, SPEAKER_โ€ฆ

๐Ÿ“… Published: Feb. 16, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25393 - Smoothwall Express 3.1 'smoothinfo.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation. Attackers can submit POST requests to the smoothinfo.cgi endpoint with script payloaโ€ฆ

๐Ÿ“… Published: Feb. 16, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25392 - Smoothwall Express 3.1 'iptools.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the IP parameter. Attackers can send POST requests to the iptools.cgi endpoint with script payloads in the IP parโ€ฆ

๐Ÿ“… Published: Feb. 16, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

4.8

CVSS4.0

CVE-2019-25390 - Smoothwall Express 3.1 'interfaces.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the interfaces.cgi script that allow attackers to inject malicious scripts through multiple parameters including GREEN_ADDRESS, GREEN_NETMASK, RED_DHCP_HOSTNAME, RED_ADDRESS, DNS1_OVEโ€ฆ

๐Ÿ“… Published: Feb. 16, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.
Total resulsts: 346578
Page 1356 of 34,658
ยซ previous page ยป next page
Filters