|
1721
|
4.8 |
MEDIUM
Network
|
gnu
|
wget2
|
wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpos…
|
CWE-20
Improper Input Validation
|
CVE-2026-1858
|
2026-05-5 11:47 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1722
|
9.8 |
CRITICAL
Network
|
tenda
|
w3002r_firmware a302_firmware w309r_firmware
|
Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient se…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2018-25317
|
2026-05-5 11:46 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1723
|
8.8 |
HIGH
Network
|
geovision
|
gv-lpc2011_firmware gv-lpc2211_firmware
|
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An…
|
CWE-78
OS Command
|
CVE-2026-42364
|
2026-05-5 11:45 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1724
|
6.5 |
MEDIUM
Network
|
geovision
|
gv-lpc2011_firmware gv-lpc2211_firmware
|
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-42367
|
2026-05-5 11:45 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1725
|
7.5 |
HIGH
Network
|
geovision
|
gv-lpc2011_firmware gv-lpc2211_firmware
|
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. …
|
CWE-341
Predictable from Observable State
|
CVE-2026-42365
|
2026-05-5 11:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1726
|
6.1 |
MEDIUM
Network
|
geovision
|
gv-lpc2011_firmware gv-lpc2211_firmware
|
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an ar…
|
CWE-79
Cross-site Scripting
|
CVE-2026-42366
|
2026-05-5 11:43 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1727
|
9.9 |
CRITICAL
Network
|
geovision
|
gv-lpc2011_firmware gv-lpc2211_firmware
|
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attack…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-42368
|
2026-05-5 11:43 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1728
|
9.8 |
CRITICAL
Network
|
geovision
|
gv-vms_firmware
|
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker ca…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-42370
|
2026-05-5 11:42 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1729
|
9.3 |
CRITICAL
Network
|
geovision
|
gv-ip_device_utility
|
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An att…
|
CWE-656
Reliance on Security Through Obscurity
|
CVE-2026-7161
|
2026-05-5 11:39 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1730
|
6.1 |
MEDIUM
Network
|
geovision
|
gv-lpc2011_firmware gv-lpc2211_firmware
|
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an ar…
|
CWE-79
Cross-site Scripting
|
CVE-2026-7371
|
2026-05-5 11:39 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|