|
581
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipul…
New
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-7468
|
2026-04-30 23:52 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
582
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-6498
|
2026-04-30 23:52 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
583
|
7.5 |
HIGH
Network
|
-
|
-
|
The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned '…
New
|
CWE-285
Improper Authorization
|
CVE-2026-2892
|
2026-04-30 23:52 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
584
|
6.1 |
MEDIUM
Network
|
frappe
|
press
|
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected XSS…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-41430
|
2026-04-30 23:51 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
585
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A security flaw has been discovered in Tenda F456 1.0.0.5. The impacted element is the function fromSetIpBind of the file /goform/SetIpBind of the component httpd. The manipulation of the argument pa…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7078
|
2026-04-30 23:38 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
586
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A weakness has been identified in Tenda F456 1.0.0.5. This affects the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. This manipulation of the argument wanmode causes bu…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7079
|
2026-04-30 23:37 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
587
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A security vulnerability has been detected in Tenda F456 1.0.0.5. This impacts the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. Such manipulation of the ar…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7080
|
2026-04-30 23:35 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
588
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A vulnerability was detected in Tenda F456 1.0.0.5. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7081
|
2026-04-30 23:30 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
589
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A flaw has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Executing a manipulation of the arg…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7082
|
2026-04-30 23:28 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
590
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of th…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7097
|
2026-04-30 23:27 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|