Thu, Jun 29 · 11:29 PM CDTCVE-2017-10684
9.8/10 · Must read/watchNVDvuln
Summary
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
CVECVE-2017-10684
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jun 29 · 11:29 PM CDT
ModifiedThu, Jul 23 · 06:58 PM CDT
Thu, Jun 29 · 11:29 PM CDTCVE-2017-10685
9.8/10 · Must read/watchNVDvuln
Summary
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
CVECVE-2017-10685
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jun 29 · 11:29 PM CDT
ModifiedThu, Jul 23 · 06:58 PM CDT
Mon, Mar 31 · 11:15 PM CDTCVE-2025-24259
9.8/10 · Must read/watchNVDvuln
Summary
This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
CVECVE-2025-24259
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 31 · 11:15 PM CDT
ModifiedThu, Jul 23 · 02:16 PM CDT
Wed, Apr 08 · 09:17 PM CDTCVE-2026-39892
9.8/10 · Must read/watchNVDvuln
Summary
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
CVECVE-2026-39892
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 09:17 PM CDT
ModifiedThu, Jul 23 · 12:17 PM CDT
Wed, Jan 07 · 05:15 PM CSTCVE-2025-12543
9.6/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling at
CVECVE-2025-12543
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 07 · 05:15 PM CST
ModifiedFri, Jul 24 · 04:16 AM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedThu, Jul 23 · 12:17 PM CDT
Sun, Apr 05 · 01:17 PM CDTCVE-2026-5566
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBind results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.
CVECVE-2026-5566
SeverityHIGH
TypeUPDATED
PublishedSun, Apr 05 · 01:17 PM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Sun, Apr 05 · 01:17 PM CDTCVE-2026-5567
8.8/10 · Worth your timeNVDvuln
Summary
A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been publi
CVECVE-2026-5567
SeverityHIGH
TypeUPDATED
PublishedSun, Apr 05 · 01:17 PM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 12:16 AM CDTCVE-2026-5605
8.8/10 · Worth your timeNVDvuln
Summary
A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used f
CVECVE-2026-5605
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 12:16 AM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 01:16 AM CDTCVE-2026-5608
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability was detected in Belkin F9K1122 1.00.33. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted
CVECVE-2026-5608
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 01:16 AM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 02:16 AM CDTCVE-2026-5609
8.8/10 · Worth your timeNVDvuln
Summary
A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parameter Handler. This manipulation of the argument index/wl_radio causes stack-based buffer overflow. It is possible to initiate the attack remotely. The ex
CVECVE-2026-5609
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 02:16 AM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 02:16 AM CDTCVE-2026-5610
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability has been found in Belkin F9K1015 1.00.10. Affected by this issue is the function formWISP5G of the file /goform/formWISP5G. Such manipulation of the argument webpage leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may b
CVECVE-2026-5610
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 02:16 AM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 03:16 AM CDTCVE-2026-5613
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability was identified in Belkin F9K1015 1.00.10. This issue affects the function formReboot of the file /goform/formReboot. The manipulation of the argument webpage leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was co
CVECVE-2026-5613
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 03:16 AM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 04:16 AM CDTCVE-2026-5614
8.8/10 · Worth your timeNVDvuln
Summary
A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used f
CVECVE-2026-5614
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 04:16 AM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 06:16 AM CDTCVE-2026-5628
8.8/10 · Worth your timeNVDvuln
Summary
A security vulnerability has been detected in Belkin F9K1015 1.00.10. Impacted is the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. The manipulation of the argument webpage leads to stack-based buffer overflow. Remote exploitation of the attack is possible. T
CVECVE-2026-5628
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 06:16 AM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 06:16 AM CDTCVE-2026-5629
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability was detected in Belkin F9K1015 1.00.10. The affected element is the function formSetFirewall of the file /goform/formSetFirewall. The manipulation of the argument webpage results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor wa
CVECVE-2026-5629
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 06:16 AM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 10:16 PM CDTCVE-2026-5685
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
CVECVE-2026-5685
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 10:16 PM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 10:16 PM CDTCVE-2026-5686
8.8/10 · Worth your timeNVDvuln
Summary
A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may
CVECVE-2026-5686
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 10:16 PM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 10:16 PM CDTCVE-2026-5687
8.8/10 · Worth your timeNVDvuln
Summary
A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. This manipulation of the argument page causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and cou
CVECVE-2026-5687
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 10:16 PM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 10:16 PM CDTCVE-2026-5707
8.8/10 · Worth your timeNVDvuln
Summary
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue,
CVECVE-2026-5707
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 10:16 PM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 10:16 PM CDTCVE-2026-5708
8.8/10 · Worth your timeNVDvuln
Summary
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and ser
CVECVE-2026-5708
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 10:16 PM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Mon, Apr 06 · 10:16 PM CDTCVE-2026-5709
8.8/10 · Worth your timeNVDvuln
Summary
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users a
CVECVE-2026-5709
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 10:16 PM CDT
ModifiedFri, Jul 24 · 09:10 AM CDT
Wed, Apr 08 · 10:16 PM CDTCVE-2026-5858
8.8/10 · Worth your timeNVDvuln
Summary
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVECVE-2026-5858
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 10:16 PM CDT
ModifiedFri, Jul 24 · 08:10 AM CDT
Wed, Apr 08 · 10:16 PM CDTCVE-2026-5859
8.8/10 · Worth your timeNVDvuln
Summary
Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVECVE-2026-5859
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 10:16 PM CDT
ModifiedFri, Jul 24 · 08:10 AM CDT
Wed, Apr 08 · 10:16 PM CDTCVE-2026-5860
8.8/10 · Worth your timeNVDvuln
Summary
Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVECVE-2026-5860
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 10:16 PM CDT
ModifiedFri, Jul 24 · 08:10 AM CDT