7.8

CVSS3.1

CVE-2026-23862 -

Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

πŸ“… Published: March 16, 2026, 5:28 p.m. πŸ”„ Last Modified: March 17, 2026, 3:55 a.m.

9.1

CVSS3.1

CVE-2026-23489 - Fields GLPI plugin vulnerable to RCE in dropdown generation

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.

πŸ“… Published: March 16, 2026, 5:12 p.m. πŸ”„ Last Modified: March 18, 2026, 1:57 p.m.

5.1

CVSS4.0

CVE-2026-4253 - Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection

A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of the component Web Interface. The manipulation of the argument wans.policy.list1 results in os command injection. It is possible to launch the attack r…

πŸ“… Published: March 16, 2026, 5:02 p.m. πŸ”„ Last Modified: March 20, 2026, 12:55 p.m.

5.1

CVSS4.0

CVE-2026-29510 - Hereta ETH-IMC408M Stored XSS via Device Name

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by manipulating the Device Name field. Attackers can inject malicious scripts through the System Status interface that execute …

πŸ“… Published: March 16, 2026, 4:56 p.m. πŸ”„ Last Modified: March 17, 2026, 4:16 p.m.

5.1

CVSS4.0

CVE-2026-29513 - Hereta ETH-IMC408M Stored XSS via Device Location

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by manipulating the Device Location field. Attackers can inject malicious scripts through the System Status interface that exec…

πŸ“… Published: March 16, 2026, 4:56 p.m. πŸ”„ Last Modified: March 17, 2026, 4:16 p.m.

5.1

CVSS4.0

CVE-2026-29520 - Hereta ETH-IMC408M Reflected XSS via ping_ipaddr Parameter

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute arbitrary JavaScript. Attackers can craft malicious links with injected script payloads in the ping_ipaddr parameter to…

πŸ“… Published: March 16, 2026, 4:55 p.m. πŸ”„ Last Modified: March 17, 2026, 4:16 p.m.

5.1

CVSS4.0

CVE-2026-29521 - Hereta ETH-IMC408M CSRF via Configuration Setup

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing CSRF protections in setup.cgi. Attackers can host malicious pages that submit forged requests using automatically-includ…

πŸ“… Published: March 16, 2026, 4:55 p.m. πŸ”„ Last Modified: March 17, 2026, 4:16 p.m.

9.3

CVSS4.0

CVE-2026-4252 - Tenda AC8 IPv6 check_is_ipv6 ip address for authentication

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and mig…

πŸ“… Published: March 16, 2026, 4:32 p.m. πŸ”„ Last Modified: March 17, 2026, 9:52 a.m.

6.8

CVSS4.0

CVE-2026-4270 - AWS API MCP File Access Restriction Bypass

Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To re…

πŸ“… Published: March 16, 2026, 4:07 p.m. πŸ”„ Last Modified: March 17, 2026, 9:52 a.m.

2

CVSS4.0

CVE-2026-4251 - CityData CityChat ai.citydata.citychat credentials.json credentials storage

A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknown functionality of the file resources/assets/flutter_assets/assets/credentials.json of the component ai.citydata.citychat. Executing a manipulation can lead to unprotected storage…

πŸ“… Published: March 16, 2026, 4:02 p.m. πŸ”„ Last Modified: March 17, 2026, 9:52 a.m.
Total resulsts: 338998
Page 78 of 33,900
Β« previous page Β» next page
Filters