|
591
|
7.5 |
HIGH
Adjacent
|
vmware
|
spring_boot
|
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the att…
New
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-40972
|
2026-04-30 23:26 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
592
|
7.0 |
HIGH
Local
|
vmware
|
spring_boot
|
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack p…
New
|
CWE-377
Insecure Temporary File
|
CVE-2026-40973
|
2026-04-30 23:25 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
593
|
3.7 |
LOW
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can ex…
New
|
CWE-362
Race Condition
|
CVE-2026-41913
|
2026-04-30 23:15 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
594
|
4.8 |
MEDIUM
Network
|
dlink
|
dgs-3420-28tc_firmware
|
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7026
|
2026-04-30 23:11 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
595
|
4.8 |
MEDIUM
Network
|
dlink
|
dsl-2740r_firmware
|
A vulnerability was identified in D-Link DSL-2740R EU_01.15. Impacted is an unknown function of the component Wireless Setup Section. Such manipulation of the argument Wireless Network Name leads to …
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7027
|
2026-04-30 23:10 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
596
|
8.8 |
HIGH
Network
|
tenda
|
fh1202_firmware
|
A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Performing a manipulation of the ar…
Update
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-7034
|
2026-04-30 23:10 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
597
|
8.8 |
HIGH
Network
|
tenda
|
fh1202_firmware
|
A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. Executing a manipulation of the argument G…
Update
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-7035
|
2026-04-30 23:10 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
598
|
9.8 |
CRITICAL
Network
|
tenda
|
i9_firmware
|
A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal…
Update
|
CWE-22
Path Traversal
|
CVE-2026-7036
|
2026-04-30 23:10 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
599
|
8.8 |
HIGH
Network
|
tenda
|
hg10_firmware
|
A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the function formRoute of the file /boaform/formRouting of the component Boa Service. This manipulation of the…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-6988
|
2026-04-30 23:10 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
600
|
8.8 |
HIGH
Network
|
tenda
|
f453_firmware
|
A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injecti…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6989
|
2026-04-30 23:10 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|