9.8

CVSS3.1

CVE-2026-25200 - Stored XSS via Unrestricted HTML Upload in Samsung MagicINFO 9 Server

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.

๐Ÿ“… Published: Feb. 2, 2026, 4:49 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1 a.m.

8.7

CVSS4.0

CVE-2026-24788 - OS Command Injection in RaspAP raspapโ€‘webgui Allowing Remote Execution

RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.

๐Ÿ“… Published: Feb. 2, 2026, 4:37 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1 a.m.

4.8

CVSS4.0

CVE-2026-1744 - D-Link DSL-6641K sp_pppoe_user.js doSubmitPPP cross site scripting

A vulnerability was found in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function doSubmitPPP of the file sp_pppoe_user.js. The manipulation of the argument Username results in cross site scripting. The attack may be launched remotely. The exploit has been made public and coulโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 4:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1 a.m.

2.3

CVSS4.0

CVE-2026-1743 - DJI Mavic Mini/Air/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replay

A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass by capture-replay. The attack must be carried out from withiโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 4:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1 a.m.

5.1

CVSS4.0

CVE-2026-1742 - EFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted upload

A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi of the component VPN Service. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit โ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 3:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:45 p.m.

7.5

CVSS4.0

CVE-2026-1741 - EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor

A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is possible to initiate the attack remotely. The complexity of an aโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 3:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1 a.m.

6.9

CVSS4.0

CVE-2026-1740 - EFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authenticaโ€ฆ

A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup Interface. The manipulation results in improper authentication. The attack may be performed from remote. The exploit has โ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 2:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:30 p.m.

6.9

CVSS4.0

CVE-2026-1739 - Free5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereference

A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the file internal/sbi/processor/smpolicy.go. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The exploit has been disclosed to tโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 2:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1 a.m.

8.5

CVSS4.0

CVE-2025-13348 -

An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local user sending a specially crafted request, potentially leading to the creation of arbitrary files in a specified path. Refer to the "Security Update fโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 2 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2026-1738 - Open5GS SGWC context.c sgwc_tunnel_add assertion

A flaw has been found in Open5GS up to 2.7.6. The impacted element is the function sgwc_tunnel_add of the file /src/sgwc/context.c of the component SGWC. Executing a manipulation of the argument pdr can lead to reachable assertion. The attack can be executed remotely. The exploit has been publishedโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 1:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:45 p.m.
Total resulsts: 349182
Page 1866 of 34,919
ยซ previous page ยป next page
Filters