Aggregator
CVE-2026-11557 | Tenda F451 1.0.0.7/1.0.0.9 Web Management Interface /goform/Natlimit fromNatlimit page stack-based overflow
2 weeks 3 days ago
A vulnerability classified as critical was found in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead to stack-based buffer overflow.
This vulnerability is handled as CVE-2026-11557. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2026-11556 | Tenda F451 1.0.0.7/1.0.0.9 Web Management Interface /goform/WriteFacMac formWriteFacMac mac os command injection
2 weeks 3 days ago
A vulnerability classified as critical has been found in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection.
This vulnerability is known as CVE-2026-11556. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
谷歌Gemini API再BUG 有开发者每小时被收取200美元缓存费且无法删除缓存
2 weeks 3 days ago
Over 20,000 Instagram accounts stolen in Meta AI support hack
2 weeks 3 days ago
Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords. [...]
Sergiu Gatlan
Submit #836791: codeastro Payroll System V1.0 SQL Injection [Accepted]
2 weeks 3 days ago
Submit #836791 / VDB-369169
SchneiderGrace
Submit #836787: codeastro Payroll System V1.0 SQL Injection [Duplicate]
2 weeks 3 days ago
Submit #836787 / VDB-367579
SchneiderGrace
Submit #836790: codeastro Payroll System V1.0 SQL Injection [Duplicate]
2 weeks 3 days ago
Submit #836790 / VDB-369168
SchneiderGrace
Submit #836785: codeastro Payroll System V1.0 SQL Injection [Accepted]
2 weeks 3 days ago
Submit #836785 / VDB-369168
cshwswwsshd99
CVE-2026-11555 | D-Link DGS-1100-08PD 1.00.006 Web Interface /etc/boa.conf least privilege violation
2 weeks 3 days ago
A vulnerability described as critical has been identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation.
This vulnerability is traded as CVE-2026-11555. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #836477: Tenda Tenda F451 Wireless Router V1.0.0.7, V1.0.0.9 Stack-based Buffer Overflow [Accepted]
2 weeks 3 days ago
Submit #836477 / VDB-369167
hacker128
Submit #836476: Tenda Tenda F451 Wireless Router V1.0.0.7, V1.0.0.9 OS Command Injection [Accepted]
2 weeks 3 days ago
Submit #836476 / VDB-369166
hacker128
Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets
2 weeks 3 days ago
AI-powered coding tools are rapidly changing how developers build and ship software. But as these tools enter everyday development pipelines, they are also opening new doors for attackers. A recently uncovered vulnerability in a widely used AI coding assistant shows just how far that risk can go. Researchers found that GitHub Actions workflows powered by […]
The post Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets appeared first on Cyber Security News.
Tushar Subhra Dutta
Submit #834824: D-link DGS-1100-08PD v1.00.006 Misconfiguration [Accepted]
2 weeks 3 days ago
Submit #834824 / VDB-369165
yinfantasy
CVE-2026-11554 | TOTOLINK CP450 4.1.0cu.747 vsftpd /etc/vsftpd.conf least privilege violation
2 weeks 3 days ago
A vulnerability marked as critical has been reported in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation.
This vulnerability appears as CVE-2026-11554. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2026-11553 | Tenda HG7HG9/HG10 300001138_en_xpon /boaform/formPPPEdit encodename stack-based overflow
2 weeks 3 days ago
A vulnerability labeled as critical has been found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-11553. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
D. Lgs. 96 del 2026: Trasparenza retributiva
2 weeks 3 days ago
E' stato approvato e pubblicato il D. Lgs. 96 del 2026 sulla trasparenza retributiva: https://www.
Submit #834821: TOTOLink CP450 V4.1.0cu.747 Misconfiguration [Accepted]
2 weeks 3 days ago
Submit #834821 / VDB-369164
L-14
Submit #836778: Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon stack-based buffer overflow [Accepted]
2 weeks 3 days ago
Submit #836778 / VDB-369163
zhihua xie
Никакого взлома — только звонки и обаяние. Хакеры разводят бизнес по схеме из телефонных колл-центров
2 weeks 3 days ago
В новой тактике вымогателей от первого контакта до кражи данных проходит менее часа.