Latest CVE Feed
-
9.0
HIGHCVE-2026-2925
A vulnerability was detected in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_42B5A0 of the file /boafrm/formBridgeVlan of the component Bridge VLAN Configuration Endpoint. Performing a manipulation of the argument submit-url results... Read more
Affected Products : dwr-m960_firmware- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
2.5
LOWCVE-2026-2913
A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the l... Read more
Affected Products : libvips- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2026-2912
A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation of the argument test_id results in sql injection. It is... Read more
Affected Products : online_reviewer_system- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Injection
-
9.0
HIGHCVE-2026-2911
A vulnerability has been found in Tenda FH451 up to 1.0.0.9. This issue affects some unknown processing of the file /goform/GstDhcpSetSer. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disc... Read more
Affected Products : fh451_firmware- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2910
A flaw has been found in Tenda HG9 300001138. This vulnerability affects unknown code of the file /boaform/formPing6. Executing a manipulation of the argument pingAddr can lead to stack-based buffer overflow. The attack may be performed from remote. The e... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2909
A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Performing a manipulation of the argument pingAddr results in stack-based buffer overflow. The attac... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2908
A security vulnerability has been detected in Tenda HG9 300001138. Affected by this issue is some unknown functionality of the file /boaform/formLoopBack of the component Loopback Detection Configuration Endpoint. Such manipulation of the argument Ethtype... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2907
A weakness has been identified in Tenda HG9 300001138. Affected by this vulnerability is an unknown functionality of the file /boaform/formgponConf of the component GPON Configuration Endpoint. This manipulation of the argument fmgpon_loid/fmgpon_loid_pas... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2906
A security flaw has been discovered in Tenda HG9 300001138. Affected is an unknown function of the file /boaform/formSamba of the component Samba Configuration Endpoint. The manipulation of the argument sambaCap results in stack-based buffer overflow. The... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2905
A vulnerability was identified in Tenda HG9 300001138. This impacts an unknown function of the file /boaform/formWlanSetup of the component Wireless Configuration Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The at... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2904
A vulnerability was determined in UTT HiPER 810G 1.7.7-171114. This affects the function strcpy of the file /goform/ConfigExceptAli. Executing a manipulation can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly d... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2026-2903
A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack can only be executed locally. The exploit has been publish... Read more
Affected Products : re2c- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2026-2898
A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserializ... Read more
Affected Products : funadmin- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2026-2897
A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross site sc... Read more
Affected Products : funadmin- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2026-2896
A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can... Read more
Affected Products : funadmin- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2026-2895
A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery.... Read more
Affected Products : funadmin- Published: Feb. 21, 2026
- Modified: Feb. 21, 2026
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2026-2894
A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. T... Read more
Affected Products : funadmin- Published: Feb. 21, 2026
- Modified: Feb. 21, 2026
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2026-2889
A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public a... Read more
Affected Products :- Published: Feb. 21, 2026
- Modified: Feb. 21, 2026
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2026-2887
A security vulnerability has been detected in aardappel lobster up to 2025.4. This impacts the function lobster::TypeName in the library dev/src/lobster/idents.h. Such manipulation leads to uncontrolled recursion. The attack can only be performed from a l... Read more
Affected Products : lobster- Published: Feb. 21, 2026
- Modified: Feb. 21, 2026
- Vuln Type: Denial of Service
-
9.0
HIGHCVE-2026-2886
A weakness has been identified in Tenda A21 1.0.0.0. This affects the function set_device_name of the file /goform/SetOnlineDevName. This manipulation of the argument devName causes stack-based buffer overflow. It is possible to initiate the attack remote... Read more
Affected Products :- Published: Feb. 21, 2026
- Modified: Feb. 21, 2026
- Vuln Type: Memory Corruption