5.1

CVSS4.0

CVE-2026-32839 - Edimax GS-5008PL <= 1.00.54 CSRF via Management CGI Endpoints

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and re…

πŸ“… Published: March 17, 2026, 9:42 p.m. πŸ”„ Last Modified: March 19, 2026, 2:06 p.m.

5.1

CVSS4.0

CVE-2026-32840 - Edimax GS-5008PL <= 1.00.54 Stored XSS via Device Name

Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payl…

πŸ“… Published: March 17, 2026, 9:42 p.m. πŸ”„ Last Modified: March 19, 2026, 2:04 p.m.

7.1

CVSS4.0

CVE-2026-32842 - Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext

Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username an…

πŸ“… Published: March 17, 2026, 9:41 p.m. πŸ”„ Last Modified: March 19, 2026, 1:54 p.m.

9.2

CVSS4.0

CVE-2026-32841 - Edimax GS-5008PL <= 1.00.54 Global Authentication State Across All Clients

Edimax GS-5008PL firmware version 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any use…

πŸ“… Published: March 17, 2026, 9:41 p.m. πŸ”„ Last Modified: March 19, 2026, 2:03 p.m.

6.3

CVSS4.0

CVE-2026-4349 - Duende IdentityServer Token Renewal Endpoint authorize improper authentication

A vulnerability was determined in Duende IdentityServer 4. The affected element is an unknown function of the file /connect/authorize of the component Token Renewal Endpoint. This manipulation of the argument id_token_hint causes improper authentication. It is possible to initiate the attack remote…

πŸ“… Published: March 17, 2026, 9:32 p.m. πŸ”„ Last Modified: March 18, 2026, 2:52 p.m.

6.7

CVSS4.0

CVE-2026-2809 - Endpoint DLP Driver DLL

Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger an integer overflow within the DLL Injector, leading to a Blue-Screen-of-Death (BSOD). Successful …

πŸ“… Published: March 17, 2026, 8:20 p.m. πŸ”„ Last Modified: March 18, 2026, 2:52 p.m.

2

CVSS4.0

CVE-2026-4359 - Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

πŸ“… Published: March 17, 2026, 7:42 p.m. πŸ”„ Last Modified: March 18, 2026, 2:52 p.m.

6.5

CVSS3.1

CVE-2026-25936 - GLPI Vulnerable to Authenticated SQL Injection

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

πŸ“… Published: March 17, 2026, 7:41 p.m. πŸ”„ Last Modified: March 19, 2026, 7:30 p.m.

8.7

CVSS4.0

CVE-2026-32981 - Ray Dashboard <= 2.8.0 Path Traversal Leading to Local File Disclosure

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside th…

πŸ“… Published: March 17, 2026, 7:33 p.m. πŸ”„ Last Modified: March 19, 2026, 7:25 p.m.

5.5

CVSS3.1

CVE-2026-3563 -

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of serv…

πŸ“… Published: March 17, 2026, 7:15 p.m. πŸ”„ Last Modified: March 19, 2026, 1:04 p.m.
Total resulsts: 339266
Page 93 of 33,927
Β« previous page Β» next page
Filters