7.5

CVSS3.1

CVE-2026-6857 - Camel-infinispan: camel-infinispan: remote code execution via unsafe deserialization

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gaiโ€ฆ

๐Ÿ“… Published: April 13, 2026, midnight ๐Ÿ”„ Last Modified: April 27, 2026, 8:21 p.m.

5.5

CVSS3.1

CVE-2026-6843 - Nano: nano: format string vulnerability leads to denial of service

A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Sโ€ฆ

๐Ÿ“… Published: April 13, 2026, midnight ๐Ÿ”„ Last Modified: April 27, 2026, 8:21 p.m.

8.7

CVSS4.0

CVE-2026-6137 - Tenda F451 AdvSetWan fromAdvSetWan stack-based overflow

A vulnerability was detected in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromAdvSetWan of the file /goform/AdvSetWan. The manipulation of the argument wanmode/PPPOEPassword results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit iโ€ฆ

๐Ÿ“… Published: April 12, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 12:35 p.m.

8.7

CVSS4.0

CVE-2026-6136 - Tenda F451 L7Im frmL7ImForm stack-based overflow

A security vulnerability has been detected in Tenda F451 1.0.0.7_cn_svn7958. Impacted is the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publโ€ฆ

๐Ÿ“… Published: April 12, 2026, 11:30 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 12:36 p.m.

8.7

CVSS4.0

CVE-2026-6135 - Tenda F451 SetIpBind fromSetIpBind stack-based overflow

A weakness has been identified in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made avaโ€ฆ

๐Ÿ“… Published: April 12, 2026, 11:15 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 12:36 p.m.

8.7

CVSS4.0

CVE-2026-6134 - Tenda F451 qossetting fromqossetting stack-based overflow

A security flaw has been discovered in Tenda F451 1.0.0.7_cn_svn7958. This vulnerability affects the function fromqossetting of the file /goform/qossetting. Performing a manipulation of the argument qos results in stack-based buffer overflow. The attack is possible to be carried out remotely. The eโ€ฆ

๐Ÿ“… Published: April 12, 2026, 11 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 12:37 p.m.

8.7

CVSS4.0

CVE-2026-6133 - Tenda F451 SafeUrlFilter fromSafeUrlFilter stack-based overflow

A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. This affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and migโ€ฆ

๐Ÿ“… Published: April 12, 2026, 10:45 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 12:38 p.m.

9.3

CVSS4.0

CVE-2026-6132 - Totolink A7100RU CGI cstecgi.cgi setLedCfg os command injection

A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. Remote exploitation of the attack is possiblโ€ฆ

๐Ÿ“… Published: April 12, 2026, 10:30 p.m. ๐Ÿ”„ Last Modified: April 13, 2026, 5:55 p.m.

9.3

CVSS4.0

CVE-2026-6131 - Totolink A7100RU CGI cstecgi.cgi setTracerouteCfg os command injection

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument command results in os command injection. The attack may be launched remโ€ฆ

๐Ÿ“… Published: April 12, 2026, 10:15 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 4:33 p.m.

6.9

CVSS4.0

CVE-2026-6130 - chatboxai chatbox Model Context Protocol Server Management System ipc-stdio-transport.ts StdioClienโ€ฆ

A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server Management System. Executing a manipulation of the argument args/env can lead to os command injectioโ€ฆ

๐Ÿ“… Published: April 12, 2026, 10 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 5:58 p.m.
Total resulsts: 349182
Page 516 of 34,919
ยซ previous page ยป next page
Filters