|
1001
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parame…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7394
|
2026-04-30 03:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1002
|
8.6 |
HIGH
Network
|
-
|
-
|
A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could ca…
|
CWE-130
Improper Handling of Length Parameter Inconsistency
|
CVE-2026-5367
|
2026-04-30 03:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1003
|
6.5 |
MEDIUM
Network
|
vmware
|
spring_ai
|
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`.
Affected versions:
Spring AI: 1.0.0 - 1.…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40980
|
2026-04-30 03:15 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1004
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix off-by-8 bounds check in check_wsl_eas()
The bounds check uses (u8 *)ea + nlen + 1 + vlen as the end of the EA
n…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-31614
|
2026-04-30 03:03 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1005
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulation leads to buffer overflow. Re…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7101
|
2026-04-30 02:42 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1006
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the argument mac results in comm…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7102
|
2026-04-30 02:41 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1007
|
5.5 |
MEDIUM
Local
|
foxit
|
pdf_editor pdf_reader
|
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.
|
CWE-248
Uncaught Exception
|
CVE-2026-5937
|
2026-04-30 02:31 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1008
|
5.5 |
MEDIUM
Local
|
foxit
|
pdf_editor pdf_reader
|
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
|
CWE-691
Insufficient Control Flow Management
|
CVE-2026-5938
|
2026-04-30 02:29 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1009
|
5.5 |
MEDIUM
Local
|
foxit
|
pdf_editor pdf_reader
|
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
|
CWE-416
Use After Free
|
CVE-2026-5939
|
2026-04-30 02:28 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1010
|
5.5 |
MEDIUM
Local
|
foxit
|
pdf_editor pdf_reader
|
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
|
CWE-416
Use After Free
|
CVE-2026-5940
|
2026-04-30 02:26 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|