|
4061
|
8.8 |
HIGH
Network
|
-
|
-
|
NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or con…
|
CWE-183
Permissive List of Allowed Inputs
|
CVE-2026-29514
|
2026-05-6 04:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4062
|
7.5 |
HIGH
Network
|
-
|
-
|
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-37459
|
2026-05-6 04:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4063
|
- |
|
-
|
-
|
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allow unauthenticated remote attackers to execute arbitrary shell…
|
CWE-78
OS Command
|
CVE-2026-41922
|
2026-05-6 04:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4064
|
- |
|
-
|
-
|
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthenticated remote attackers to execute arbitrary shel…
|
CWE-78
OS Command
|
CVE-2026-41923
|
2026-05-6 04:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4065
|
- |
|
-
|
-
|
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unauthenticated remote attackers to execute arbitrary s…
|
CWE-78
OS Command
|
CVE-2026-41924
|
2026-05-6 04:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4066
|
- |
|
-
|
-
|
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that allows unauthenticated remote attackers to exec…
|
CWE-78
OS Command
|
CVE-2026-41925
|
2026-05-6 04:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4067
|
- |
|
-
|
-
|
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request handlers that apply insufficient input validation.…
|
CWE-78
OS Command
|
CVE-2026-41926
|
2026-05-6 04:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4068
|
- |
|
-
|
-
|
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firewall.cgi and makeRequest.cgi binaries that allows unauthenticated attackers to o…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-41927
|
2026-05-6 04:47 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4069
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
|
CWE-158
Improper Neutralization of Null Byte or NUL Character
|
CVE-2026-43859
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4070
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
|
CWE-193
Off-by-one Error
|
CVE-2026-43860
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|