Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2015-20114 — RealtyScript 4.0.2 Cross-Site Scripting via Multiple Parameters

Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious input through multiple para…

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.9 MEDIUM
CVE-2015-20113 — RealtyScript 4.0.2 Multiple Cross-Site Request Forgery and Persistent Cross-Site Scriptin…

Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malici…

Remote | Cross-Site Request Forgery
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
8.7 HIGH
CVE-2013-20006 — Qool CMS Multiple Persistent Cross-Site Scripting Vulnerabilities

Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being stored and returned to users…

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.9 MEDIUM
CVE-2013-20005 — Qool CMS 2.0 RC2 Cross-Site Request Forgery via adduser

Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious web pages. Attackers c…

Remote | Cross-Site Request Forgery
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4185 — GPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflow

A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_def_bits_jpeg of the file src/scene_manager/swf_parse.c of the component MP4Box.…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4184 — D-Link DIR-816 goahead form2Wl5BasicSetup.cgi stack-based overflow

A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4183 — D-Link DIR-816 goahead form2WlanBasicSetup.cgi stack-based overflow

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4182 — D-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow

A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4181 — D-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow

A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
7.1 HIGH
CVE-2026-28522 — arduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of Service

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP p…

| Denial of Service
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
8.8 HIGH
CVE-2026-28519 — arduino-TuyaOpen DnsServer Heap-Based Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can se…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
7.7 HIGH
CVE-2026-28521 — arduino-TuyaOpen TuyaIoT Out-of-Bounds Memory Read Information Disclosure

arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP e…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
8.6 HIGH
CVE-2026-28520 — arduino-TuyaOpen WiFiMulti Single-Byte Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
7.2 HIGH
CVE-2016-20032 — ZKTeco ZKAccess Security System 5.3.1 Stored XSS

ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the …

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.8 MEDIUM
CVE-2016-20031 — ZKTeco ZKBioSecurity 3.0 Local Authorization Bypass via visLogin.jsp

ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers …

| Authentication
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
9.8 CRITICAL
CVE-2016-20030 — ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attac…

Remote | Authentication
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.9 MEDIUM
CVE-2016-20029 — ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipu…

| Path Traversal
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
5.3 MEDIUM
CVE-2016-20028 — ZKTeco ZKBioSecurity 3.0 Cross-Site Request Forgery Superadmin

ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Atta…

Remote | Cross-Site Request Forgery
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.1 MEDIUM
CVE-2016-20027 — ZKTeco ZKBioSecurity 3.0 Multiple Reflected XSS Vulnerabilities

ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script code by injecting malicious payloads through unsani…

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
9.8 CRITICAL
CVE-2016-20026 — ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with har…

Remote | Authentication
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
Showing 20 of 5290 Results