|
681
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A security flaw has been discovered in Tenda F456 1.0.0.5. The impacted element is the function fromSetIpBind of the file /goform/SetIpBind of the component httpd. The manipulation of the argument pa…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7078
|
2026-04-30 23:38 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
682
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A weakness has been identified in Tenda F456 1.0.0.5. This affects the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. This manipulation of the argument wanmode causes bu…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7079
|
2026-04-30 23:37 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
683
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A security vulnerability has been detected in Tenda F456 1.0.0.5. This impacts the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. Such manipulation of the ar…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7080
|
2026-04-30 23:35 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
684
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A vulnerability was detected in Tenda F456 1.0.0.5. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7081
|
2026-04-30 23:30 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
685
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A flaw has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Executing a manipulation of the arg…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7082
|
2026-04-30 23:28 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
686
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of th…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7097
|
2026-04-30 23:27 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
687
|
7.5 |
HIGH
Adjacent
|
vmware
|
spring_boot
|
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the att…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-40972
|
2026-04-30 23:26 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
688
|
7.0 |
HIGH
Local
|
vmware
|
spring_boot
|
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack p…
|
CWE-377
Insecure Temporary File
|
CVE-2026-40973
|
2026-04-30 23:25 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
689
|
3.7 |
LOW
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can ex…
|
CWE-362
Race Condition
|
CVE-2026-41913
|
2026-04-30 23:15 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
690
|
4.8 |
MEDIUM
Network
|
dlink
|
dgs-3420-28tc_firmware
|
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7026
|
2026-04-30 23:11 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|