8.7

CVSS4.0

CVE-2026-5350 - Trendnet TEW-657BRM setup.cgi update_pcdb stack-based overflow

A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is the function update_pcdb of the file /setup.cgi. The manipulation of the argument mac_pc_dba results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the p…

πŸ“… Published: April 2, 2026, 3:30 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

8.7

CVSS4.0

CVE-2026-5349 - Trendnet TEW-657BRM setup.cgi add_apcdb stack-based overflow

A vulnerability was identified in Trendnet TEW-657BRM 1.00.1. The affected element is the function add_apcdb of the file /setup.cgi. The manipulation of the argument mac_pc_dba leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be…

πŸ“… Published: April 2, 2026, 3:15 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

9.8

CVSS3.1

CVE-2026-33746 - Convoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary Users

Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature of JWT tokens. While the method configured a symmetric HMAC-SHA256 signer via lcobucci/jwt, it only validated t…

πŸ“… Published: April 2, 2026, 3:06 p.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.8

CVSS3.1

CVE-2026-33691 - OWASP CRS: Whitespace padding in filenames bypasses file upload extension checks

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespa…

πŸ“… Published: April 2, 2026, 3:03 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

7.7

CVSS3.1

CVE-2026-33544 - Tinyauth has OAuth account confusion via shared mutable state on singleton service instances

Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct fields on singleton instances shared across all concurrent r…

πŸ“… Published: April 2, 2026, 3 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

6.9

CVSS4.0

CVE-2026-5346 - huimeicloud hm_editor image-to-base64 Endpoint mcp-server.js client.get server-side request forgery

A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the component image-to-base64 Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack…

πŸ“… Published: April 2, 2026, 3 p.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.8

CVSS3.1

CVE-2026-33641 - Glances Vulnerable to Command Injection via Dynamic Configuration Values

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration parsing. This behavior occurs in Config.get_value() and is implemente…

πŸ“… Published: April 2, 2026, 2:57 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

7.1

CVSS4.0

CVE-2026-33533 - Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response. Because the XML-RPC handler does not validate the Content-Type header, an …

πŸ“… Published: April 2, 2026, 2:56 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

10

CVSS4.0

CVE-2026-32871 - FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability …

πŸ“… Published: April 2, 2026, 2:52 p.m. πŸ”„ Last Modified: April 10, 2026, 3:58 p.m.

5.4

CVSS3.1

CVE-2026-34974 - phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege Escalation

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript: URLs within SVG <a href> attributes. Any user with edit_faq permission can upload a malicious SVG that execu…

πŸ“… Published: April 2, 2026, 2:48 p.m. πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.
Total resulsts: 343921
Page 207 of 34,393
Β« previous page Β» next page
Filters