|
391
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injecti…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6989
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
392
|
3.7 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Han…
Update
|
CWE-345 CWE-347
Insufficient Verification of Data Authenticity Improper Verification of Cryptographic Signature
|
CVE-2026-6986
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
393
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. T…
Update
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-6992
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
394
|
4.0 |
MEDIUM
Network
|
-
|
-
|
Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.
New
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2026-42254
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
395
|
7.2 |
HIGH
Network
|
-
|
-
|
Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
New
|
CWE-684
Incorrect Provision of Specified Functionality
|
CVE-2026-42255
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
396
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads …
New
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7019
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
397
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The mani…
New
|
CWE-22
Path Traversal
|
CVE-2026-7020
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
398
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7023
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
399
|
4.5 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7026
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
400
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was identified in D-Link DSL-2740R EU_01.15. Impacted is an unknown function of the component Wireless Setup Section. Such manipulation of the argument Wireless Network Name leads to …
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7027
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|