5.3

CVSS4.0

CVE-2026-1601 - Totolink A7000R cstecgi.cgi setUploadUserData command injection

A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument FileName can lead to command injection. The attack can be launched remotely. The exploit has been made avai…

πŸ“… Published: Jan. 29, 2026, 6:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:06 a.m.

5.3

CVSS4.0

CVE-2025-15548 - Missing Application-Layer Encryption in Web Interface Endpoints on TP-Link VX800v

Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to intercept this traffic and compromise its confidentiality.

πŸ“… Published: Jan. 29, 2026, 6:07 p.m. πŸ”„ Last Modified: March 9, 2026, 5:52 p.m.

5.1

CVSS4.0

CVE-2025-15543 - Read-Only Root Access via USB Storage Device in TP-Link VX800v

Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem contents, giving an attacker with physical access read‑only access to system files.

πŸ“… Published: Jan. 29, 2026, 6:06 p.m. πŸ”„ Last Modified: March 9, 2026, 5:52 p.m.

6.3

CVSS4.0

CVE-2025-15542 - Denial of Service (DoS) of VoIP Communication on TP-Link VX800v

Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with crafted INVITE messages, blocking all voice lines and causing a denial of service on incoming calls.

πŸ“… Published: Jan. 29, 2026, 6:06 p.m. πŸ”„ Last Modified: March 9, 2026, 5:52 p.m.

6.9

CVSS4.0

CVE-2025-15541 - Access to System Files via SFTP on TP-Link VX800v

Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.

πŸ“… Published: Jan. 29, 2026, 6:05 p.m. πŸ”„ Last Modified: March 9, 2026, 5:51 p.m.

7.7

CVSS4.0

CVE-2025-13399 - Insecure Encryption in Communication with the Web Interface on TP-Link VX800v

A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force the weak AES key and decrypt intercepted traffic. Successful exploitation requires network proximity but no authentication, and may result in high impact to confidentiality, inte…

πŸ“… Published: Jan. 29, 2026, 6:05 p.m. πŸ”„ Last Modified: March 9, 2026, 5:51 p.m.

5.3

CVSS4.0

CVE-2026-1600 - Bdtask Bhojon All-In-One Restaurant Management System Add-to-Cart Submission Endpoint addtocart log…

A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart of the component Add-to-Cart Submission Endpoint. The manipulation of the argument price/allprice leads to business logic…

πŸ“… Published: Jan. 29, 2026, 6:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:06 a.m.

8.6

CVSS4.0

CVE-2026-24780 - AutoGPT is Vulnerable to RCE via Disabled Block Execution

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UUID w…

πŸ“… Published: Jan. 29, 2026, 5:39 p.m. πŸ”„ Last Modified: Feb. 17, 2026, 4:04 p.m.

6.8

CVSS4.0

CVE-2026-24414 - Icinga for Windows certificate can have too-open permissions

The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in …

πŸ“… Published: Jan. 29, 2026, 5:35 p.m. πŸ”„ Last Modified: March 10, 2026, 6:14 p.m.

5.3

CVSS4.0

CVE-2026-1599 - Bdtask Bhojon All-In-One Restaurant Management System Checkout placeorder logic error

A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected element is an unknown function of the file /hungry/placeorder of the component Checkout. Executing a manipulation of the argument orggrandTotal/vat/service_charge/grandtotal can lead…

πŸ“… Published: Jan. 29, 2026, 5:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:06 a.m.
Total resulsts: 344264
Page 1401 of 34,427
Β« previous page Β» next page
Filters