|
1551
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf…
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-41901
|
2026-05-14 01:10 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1552
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A flaw has been found in Open5GS up to 2.7.7. The impacted element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. This manipulation cause…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8249
|
2026-05-14 01:10 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1553
|
8.8 |
HIGH
Network
|
wavlink
|
wl-nu516u1_firmware
|
A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8228
|
2026-05-14 01:10 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1554
|
8.8 |
HIGH
Network
|
wavlink
|
wl-nu516u1_firmware
|
A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be init…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8227
|
2026-05-14 01:10 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1555
|
7.5 |
HIGH
Network
|
open5gs
|
open5gs
|
A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is the function pcf_sess_sbi_discover_and_send of the component sm-policies Endpoint. Performing a manipulation result…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8223
|
2026-05-14 01:10 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1556
|
8.8 |
HIGH
Network
|
wavlink
|
wl-nu516u1_firmware
|
A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8192
|
2026-05-14 01:10 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1557
|
8.8 |
HIGH
Network
|
wavlink
|
wl-nu516u1_firmware
|
A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os …
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8191
|
2026-05-14 01:10 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1558
|
8.8 |
HIGH
Network
|
wavlink
|
wl-nu516u1_firmware
|
A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwa…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8190
|
2026-05-14 01:10 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1559
|
8.8 |
HIGH
Network
|
wavlink
|
wl-nu516u1_firmware
|
A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Au…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8189
|
2026-05-14 01:09 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1560
|
8.8 |
HIGH
Network
|
wavlink
|
wl-nu516u1_firmware
|
A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/Encryp…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8188
|
2026-05-14 01:09 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|