8.8

CVSS3.1

CVE-2026-23780 - SQL Injection in BMC Control‑M/MFT Debug API Enables Remote Code Execution

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitr…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 7:11 p.m.

8.7

CVSS4.0

CVE-2026-5991 - Tenda F451 WrlExtraSet formWrlExtraSet stack-based overflow

A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be use…

πŸ“… Published: April 9, 2026, 11:45 p.m. πŸ”„ Last Modified: April 29, 2026, 8:03 p.m.

8.7

CVSS4.0

CVE-2026-5990 - Tenda F451 SafeEmailFilter fromSafeEmailFilter stack-based overflow

A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function fromSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclo…

πŸ“… Published: April 9, 2026, 11:30 p.m. πŸ”„ Last Modified: April 29, 2026, 8:04 p.m.

6.3

CVSS4.0

CVE-2026-5460 - Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3

A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the error handling path of TLSX_KeyShare_ProcessPqcHybridClient() in src/tls.c, the inner function TLSX_KeyShare_ProcessPqcClient_ex() frees a KyberKey object upon encountering an error.…

πŸ“… Published: April 9, 2026, 11:29 p.m. πŸ”„ Last Modified: April 29, 2026, 2 p.m.

2.3

CVSS4.0

CVE-2026-5448 - 1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore

X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing date fields from a crafted X.509 certificate via the compatibility layer API. This is only triggered when calling these two APIs directly from an application, and does not affect T…

πŸ“… Published: April 9, 2026, 11:18 p.m. πŸ”„ Last Modified: April 29, 2026, 1:56 p.m.

8.7

CVSS4.0

CVE-2026-5989 - Tenda F451 RouteStatic fromRouteStatic stack-based overflow

A flaw has been found in Tenda F451 1.0.0.7. Affected is the function fromRouteStatic of the file /goform/RouteStatic. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: April 9, 2026, 11:15 p.m. πŸ”„ Last Modified: April 30, 2026, 12:39 p.m.

2.3

CVSS4.0

CVE-2026-5392 - wolfSSL heap OOB read in PKCS7 SignedData streaming

Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bounds check is in the indefinite-length end-of-content verification loop in PKCS7_VerifySignedData().

πŸ“… Published: April 9, 2026, 11:10 p.m. πŸ”„ Last Modified: April 29, 2026, 2:02 p.m.

6.3

CVSS4.0

CVE-2026-5393 - OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS

Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-experimental and --enable-dual-alg-certs is used when building wolfSSL.

πŸ“… Published: April 9, 2026, 11:02 p.m. πŸ”„ Last Modified: April 29, 2026, 1:58 p.m.

8.7

CVSS4.0

CVE-2026-5988 - Tenda F451 AdvSetWrlsafeset formWrlsafeset stack-based overflow

A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argument mit_ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be us…

πŸ“… Published: April 9, 2026, 11 p.m. πŸ”„ Last Modified: April 29, 2026, 8:04 p.m.

9.3

CVSS4.0

CVE-2026-34424 - Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HT…

πŸ“… Published: April 9, 2026, 10:59 p.m. πŸ”„ Last Modified: April 15, 2026, 3 p.m.
Total resulsts: 349182
Page 547 of 34,919
Β« previous page Β» next page
Filters