|
3081
|
6.7 |
MEDIUM
Local
|
-
|
-
|
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scri…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-41360
|
2026-04-24 23:40 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3082
|
4.3 |
MEDIUM
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user cou…
|
CWE-285
Improper Authorization
|
CVE-2026-40305
|
2026-04-24 23:40 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3083
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An att…
|
CWE-843
Type Confusion
|
CVE-2026-6732
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3084
|
4.9 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers a…
|
CWE-807
Reliance on Untrusted Inputs in a Security Decision
|
CVE-2026-1789
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3085
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-re…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-25775
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3086
|
7.5 |
HIGH
Network
|
-
|
-
|
DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-f…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-6947
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3087
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2026-1949
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3088
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Delta Electronics AS320T has
No checking of the length of the buffer with the file name vulnerability.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-1950
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3089
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Delta Electronics AS320T has no checking of the length of the buffer with the directory name
vulnerability.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-1951
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3090
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
|
CWE-912
Hidden Functionality
|
CVE-2026-1952
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|