8.5

CVSS4.0

CVE-2026-30818 - OS Command Injection Vulnerability in dnsmasq Module in TP-Link AX53

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker t…

📅 Published: April 8, 2026, 5:54 p.m. 🔄 Last Modified: April 15, 2026, 4:15 p.m.

6.8

CVSS4.0

CVE-2026-30817 - Arbitrary File Reading Vulnerability in dnsmasq Module in TP-Link AX53

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, pot…

📅 Published: April 8, 2026, 5:53 p.m. 🔄 Last Modified: April 15, 2026, 4:15 p.m.

6.8

CVSS4.0

CVE-2026-30816 - Arbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, p…

📅 Published: April 8, 2026, 5:53 p.m. 🔄 Last Modified: April 15, 2026, 4:15 p.m.

8.5

CVSS4.0

CVE-2026-30815 - OS Command Injection Vulnerability in OpenVPN Module in TP-Link AX53

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification …

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: May 7, 2026, 4:16 p.m.

3.7

CVSS3.1

CVE-2026-34166 - LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charges str.length + pattern.length + replacement.length bytes to the memory limiter,…

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: April 13, 2026, 2:25 p.m.

7.3

CVSS4.0

CVE-2026-30814 - Buffer Overflow Vulnerability in TP-Link AX53

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow ar…

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: April 15, 2026, 4:15 p.m.

7.5

CVSS3.1

CVE-2026-33350 - LORIS has a SQL injection in MRI feedback popup

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, a SQL injection has been identified in some code sections for the MRI feedback popup window of the imaging brows…

📅 Published: April 8, 2026, 5:47 p.m. 🔄 Last Modified: April 17, 2026, 3:50 p.m.

7.8

CVSS3.1

CVE-2026-27806 - Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit

Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via exec.Command("expect", "-c", script). Because the p…

📅 Published: April 8, 2026, 5:40 p.m. 🔄 Last Modified: April 15, 2026, 4:15 p.m.

5.3

CVSS4.0

CVE-2026-39851 - Saleor has a user enumeration vulnerability due to different error messages

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.

📅 Published: April 8, 2026, 5:33 p.m. 🔄 Last Modified: April 20, 2026, 8:01 p.m.

8.4

CVSS4.0

CVE-2025-30650 - Junos OS: Privileged local user can gain access to a Linux-based FPC as root

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include…

📅 Published: April 8, 2026, 5:26 p.m. 🔄 Last Modified: April 13, 2026, 10:16 p.m.
Total resulsts: 349182
Page 584 of 34,919
« previous page » next page
Filters