|
901
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the file packages/mcp-of…
New
|
CWE-22 CWE-36
Path Traversal Absolute Path Traversal
|
CVE-2026-7217
|
2026-04-28 12:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
902
|
7.2 |
HIGH
Network
|
-
|
-
|
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could al…
New
|
CWE-78
OS Command
|
CVE-2026-1460
|
2026-04-28 12:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
903
|
6.8 |
MEDIUM
Adjacent
|
-
|
-
|
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with a…
New
|
CWE-78
OS Command
|
CVE-2026-0711
|
2026-04-28 12:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
904
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulati…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7204
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
905
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipul…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7203
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
906
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of th…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7202
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
907
|
6.8 |
MEDIUM
Network
|
-
|
-
|
A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.
New
|
CWE-78
OS Command
|
CVE-2026-32649
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
908
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
New
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-32644
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
909
|
8.8 |
HIGH
Network
|
-
|
-
|
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-20766
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
910
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-40974
|
2026-04-28 09:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|