|
1681
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulati…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7204
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1682
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipul…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7203
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1683
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of th…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7202
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1684
|
6.8 |
MEDIUM
Network
|
-
|
-
|
A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.
|
CWE-78
OS Command
|
CVE-2026-32649
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1685
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-32644
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1686
|
8.8 |
HIGH
Network
|
-
|
-
|
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-20766
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1687
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-40974
|
2026-04-28 09:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1688
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-27785
|
2026-04-28 09:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1689
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: validate inner IPv4 header length in IPTFS payload
Add validation of the inner IPv4 packet tot_len and ihl fields pa…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-31472
|
2026-04-28 08:28 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1690
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix potential deadlock in cpu hotplug with osnoise
The following sequence may leads deadlock in cpu hotplug:
task1 …
|
CWE-667
Improper Locking
|
CVE-2026-31480
|
2026-04-28 08:17 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|