Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
Showing 1,661 - 1,680 of 3,569 CVEs
CVE-2026-5996 CRITICAL - 9.8

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument tty_server leads to os command injection. It is possible to in...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5995 CRITICAL - 9.8

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument lan_info can lead to os command injection. The attack may be performed from ...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5994 CRITICAL - 9.8

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument telnet_enabled results in os command injection. The attack is possible t...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5993 CRITICAL - 9.8

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wifiOff leads to os command injection. The attack can be executed remotely...

Published: Apr 10, 2026
Source: NVD
CVE-2026-34424 CRITICAL - 9.8

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTT...

Vendor: Nextendweb
Product: Smart Slider 3 Pro for WordPress, Smart Slider 3 Pro for Joomla
Published: Apr 09, 2026
Source: NVD
CVE-2026-40154 CRITICAL - 9.3

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4....

Vendor: MervinPraison
Product: PraisonAI
Published: Apr 09, 2026
Source: NVD

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string directly to subprocess.run() with shell=True at src/praisonai-agents/praisonaiagents/memory/hooks.py. No sanitization is performed and shell metacharac...

Vendor: MervinPraison
Product: PraisonAIAgents
Published: Apr 09, 2026
Source: NVD
CVE-2026-33784 CRITICAL - 9.8

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A c...

Vendor: Juniper Networks
Product: JSI LWC
Published: Apr 09, 2026
Source: NVD
CVE-2026-5978 CRITICAL - 9.8

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument mode leads to os command injection. The attack can be initiated remotely. The ...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5977 CRITICAL - 9.8

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wifiOff can lead to os command injection. It is possible to launch the attack rem...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5976 CRITICAL - 9.8

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sambaEnabled results in os command injection. It is possible to initiate the ...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5975 CRITICAL - 9.8

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wanIdx leads to os command injection. The attack may be performed from remote. The ...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5194 CRITICAL - 9.1

Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions. This could lead to reduced security of ECDSA certificate-based authentication if...

Vendor: wolfssl
Product: wolfssl
Published: Apr 09, 2026
Source: NVD
CVE-2026-5187 CRITICAL - 9.8

Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID arc values (out[0] and out[1]), enabling a 2-byte out-of-bounds write when outSz equals 1. Second, multiple callers pass...

Vendor: wolfssl
Product: wolfssl
Published: Apr 09, 2026
Source: NVD
CVE-2026-40089 CRITICAL - 9.9

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (inclu...

Vendor: sonicverse-eu
Product: audiostreaming-stack
Published: Apr 09, 2026
Source: NVD
CVE-2026-29145 CRITICAL - 9.1

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Nativ...

Vendor: Apache Software Foundation
Product: Apache Tomcat, Apache Tomcat Native
Published: Apr 09, 2026
Source: NVD
CVE-2025-13926 CRITICAL - 9.8

An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.

Vendor: Contemporary Controls
Product: BASControl20
Published: Apr 09, 2026
Source: NVD
CVE-2026-39912 CRITICAL - 9.1

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to recei...

Vendor: v2board, cedar2025
Product: v2board, Xboard
Published: Apr 09, 2026
Source: NVD
CVE-2026-34987 CRITICAL - 9.9

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of its linear-memory sandbox. This vulnerability requires use of the Winch ...

Vendor: bytecodealliance
Product: wasmtime
Published: Apr 09, 2026
Source: NVD
CVE-2026-34971 CRITICAL - 7.8

Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the wrong address is accessed. When combined with explicit bounds checks ...

Vendor: bytecodealliance
Product: wasmtime
Published: Apr 09, 2026
Source: NVD