|
3501
|
7.8 |
HIGH
Local
|
qualcomm
|
cologne_firmware fastconnect_6900_firmware fastconnect_7800_firmware sc8380xp_firmware snapdragon_ar1_gen_1_firmware wcd9378c_firmware wcd9380_firmware wcd9385_firmware wcn786…
|
Memory corruption while processing IOCTL command when device is in power-save state.
|
CWE-749 CWE-787
Exposed Dangerous Method or Function Out-of-bounds Write
|
CVE-2026-25266
|
2026-05-7 03:02 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3502
|
9.8 |
CRITICAL
Network
|
qualcomm
|
qca7005_firmware
|
Buffer overflow due to incorrect authorization in PLC FW
|
CWE-863
Incorrect Authorization
|
CVE-2026-25293
|
2026-05-7 03:01 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3503
|
9.1 |
CRITICAL
Network
|
apache
|
opennlp
|
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0.0-M3
Description: The DictionaryEntryPersistor …
|
CWE-611
XXE
|
CVE-2026-40682
|
2026-05-7 03:00 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3504
|
9.8 |
CRITICAL
Network
|
apache
|
opennlp
|
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader
Versions Affected: before 2.5.9, before 3.0.0-M3
Description:
The ExtensionLoader.instantiateExtension(C…
|
CWE-470
Unsafe Reflection
|
CVE-2026-42027
|
2026-05-7 03:00 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3505
|
9.8 |
CRITICAL
Network
|
nginxui
|
nginx_ui
|
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/insta…
|
CWE-284 CWE-306
Improper Access Control Missing Authentication for Critical Function
|
CVE-2026-42222
|
2026-05-7 02:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3506
|
7.2 |
HIGH
Network
|
dlink
|
di-8100_firmware
|
A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The atta…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-7851
|
2026-05-7 02:40 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3507
|
9.8 |
CRITICAL
Network
|
dlink
|
di-8100_firmware
|
A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7853
|
2026-05-7 02:40 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3508
|
9.8 |
CRITICAL
Network
|
dlink
|
di-8100_firmware
|
A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler.…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7854
|
2026-05-7 02:39 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3509
|
7.2 |
HIGH
Network
|
dlink
|
di-8100_firmware
|
A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. Performing a manipulation of th…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7855
|
2026-05-7 02:38 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3510
|
7.2 |
HIGH
Network
|
dlink
|
di-8100_firmware
|
A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the component Web Management Interface. Executing a manipulation of the argument Name c…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7856
|
2026-05-7 02:36 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|