5.3

CVSS4.0

CVE-2026-6141 - danielmiessler Personal_AI_Infrastructure parse_url.ts os command injection

A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/Tools/parse_url.ts. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclo…

πŸ“… Published: April 13, 2026, 12:45 a.m. πŸ”„ Last Modified: April 24, 2026, 5:58 p.m.

9.3

CVSS4.0

CVE-2026-6140 - Totolink A7100RU CGI cstecgi.cgi UploadFirmwareFile os command injection

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument FileName results in os command injection. The attack may be initiated remotely. T…

πŸ“… Published: April 13, 2026, 12:30 a.m. πŸ”„ Last Modified: April 13, 2026, 3:19 p.m.

9.3

CVSS4.0

CVE-2026-6139 - Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The expl…

πŸ“… Published: April 13, 2026, 12:15 a.m. πŸ”„ Last Modified: April 14, 2026, 7:37 p.m.

9.3

CVSS4.0

CVE-2026-6138 - Totolink A7100RU CGI cstecgi.cgi setAccessDeviceCfg os command injection

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mac causes os command injection. The attack can be initiated remotely. The exploit…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 3:01 p.m.

2.5

CVSS3.1

CVE-2026-6842 - Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permiss…

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or i…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

2.7

CVSS3.1

CVE-2026-36952 -

Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:28 p.m.

5.5

CVSS3.1

CVE-2026-31424 - netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP Weiming Shi says: xt_match and xt_target structs registered with NFPROTO_UNSPEC can be loaded by any protocol family through nft_compat. Whe…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

2.7

CVSS3.1

CVE-2026-36923 -

Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 3:45 p.m.

2.7

CVSS3.1

CVE-2026-36919 -

Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

5.4

CVSS3.1

CVE-2025-70936 -

Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and executed in the context of an authenticated user s…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:33 p.m.
Total resulsts: 349182
Page 510 of 34,919
Β« previous page Β» next page
Filters