5.3

CVSS4.0

CVE-2026-5354 - Trendnet TEW-657BRM setup.cgi vpn_connect os command injection

A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the file /setup.cgi. Executing a manipulation of the argument policy_name can lead to os command injection. The attack can be executed remotely. The exploit has been published and may …

πŸ“… Published: April 2, 2026, 4:30 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

2.1

CVSS4.0

CVE-2026-35038 - signalk-server: Arbitrary Prototype Read via `from` Field Bypass

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal…

πŸ“… Published: April 2, 2026, 4:20 p.m. πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.

5.3

CVSS4.0

CVE-2026-5353 - Trendnet TEW-657BRM setup.cgi ping_test os command injection

A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. Performing a manipulation of the argument c4_IPAddr results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The v…

πŸ“… Published: April 2, 2026, 4:15 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

6.1

CVSS3.1

CVE-2026-34083 - signalk-server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerability in its OIDC login and logout handlers where the unvalidated HTTP Host header is used to construct the OAuth2 redirect_uri. Because the redirectUr…

πŸ“… Published: April 2, 2026, 4:14 p.m. πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.

6.9

CVSS4.0

CVE-2026-33951 - signalk-server: Unauthenticated Source Priorities Manipulation

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthenticated HTTP endpoint that allows remote attackers to modify navigation data source priorities. This endpoint, accessible via PUT /signalk/v1/api/sourc…

πŸ“… Published: April 2, 2026, 4:11 p.m. πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.

9.4

CVSS3.1

CVE-2026-33950 - signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated attacker can gain full Administrator access to the SignalK server at any time, …

πŸ“… Published: April 2, 2026, 4:08 p.m. πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.

5.3

CVSS4.0

CVE-2026-5352 - Trendnet TEW-657BRM setup.cgi edit os command injection

A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /setup.cgi. Such manipulation of the argument pcdb_list leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. T…

πŸ“… Published: April 2, 2026, 4 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

7.5

CVSS3.1

CVE-2025-65114 - Apache Traffic Server: Malformed chunked message body allows request smuggling

Apache Traffic Server allows request smuggling if chunked messages are malformed.Β  This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.

πŸ“… Published: April 2, 2026, 3:55 p.m. πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.

7.5

CVSS3.1

CVE-2025-58136 - Apache Traffic Server: A simple legitimate POST request causes a crash

A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to setΒ p…

πŸ“… Published: April 2, 2026, 3:54 p.m. πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.

5.3

CVSS4.0

CVE-2026-5351 - Trendnet TEW-657BRM setup.cgi add_wps_client os command injection

A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setup.cgi. This manipulation of the argument wl_enrolee_pin causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and co…

πŸ“… Published: April 2, 2026, 3:45 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.
Total resulsts: 343921
Page 206 of 34,393
Β« previous page Β» next page
Filters