Exploit Database

144,457 exploits tracked across all sources.

Sort: Activity Stars
CVE-2026-36801 WRITEUP HIGH
Tenda G0 15.11.0.5 - Denial of Service via IPMacBindRule Parameter Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBindRule parameter of the formIPMacBindAdd function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36802 WRITEUP HIGH
Tenda PW201A v1.0.5 - Denial of Service via SafeMacFilter Page Parameter Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow in the page parameter of the SafeMacFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36803 WRITEUP HIGH
Tenda PW201A v1.0.5 - Buffer Overflow in qossetting Page Parameter
Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow in the page parameter of the qossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36805 WRITEUP HIGH
Tenda G0 v15.11.0.5 - Multiple Buffer Overflow via Saveqqlist Function
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple buffer overflows in the Saveqqlist function via the qqStr and markStr parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36806 WRITEUP HIGH
Tenda W15E v15.11.0.10 - Denial of Service via webAuthUserPwd Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formModifyWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36807 WRITEUP HIGH
Tenda W15E 15.11.0.10 - Denial of Service via formAddWebAuthUser webAuthUserPwd Parameter Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36808 WRITEUP HIGH
Tenda W15E v15.11.0.10 - Denial of Service via webAuthUserInfo Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36809 WRITEUP HIGH
Tenda W15E 15.11.0.10 - Denial of Service via webAuthWhiteID Parameter Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteID parameter of the formModifyWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36810 WRITEUP HIGH
Tenda W15E 15.11.0.10 - Denial of Service via Buffer Overflow in formPortalAuth gotoUrl Parameter
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoUrl parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36811 WRITEUP HIGH
Tenda W15E 15.11.0.10 - Denial of Service via formDelwebAuthPic picName Parameter Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picName parameter of the formDelwebAuthPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36813 WRITEUP HIGH
Tenda W15E 15.11.0.10 - Denial of Service via picCropName Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36815 WRITEUP HIGH
Tenda W15E 15.11.0.10 - Denial of Service via Hostname Parameter Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSetNetCheckTools function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36816 WRITEUP HIGH
Tenda W15E v15.11.0.10 - Buffer Overflow in wewifiWhiteUserInfo Parameter
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36817 WRITEUP HIGH
Tenda W15E 15.11.0.10 - Buffer Overflow in formAddWebAuthWhiteUser
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36818 WRITEUP HIGH
Tenda W20E 15.11.0.6 - Denial of Service via wewifiWhiteUserInfo Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36819 WRITEUP HIGH
Tenda W20E 15.11.0.6 - Stack-based Buffer Overflow in fromSetDhcpRules via bindMACAddr Parameter
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the fromSetDhcpRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36820 WRITEUP HIGH
Tenda W20E 15.11.0.6 - Stack-based Buffer Overflow in formAddWebAuthWhiteUser
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36821 WRITEUP HIGH
Tenda W20E 15.11.0.6 - Stack-based Buffer Overflow in formCropAndSetWewifiPic
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36822 WRITEUP HIGH
Tenda W20E 15.11.0.6 - Stack-based Buffer Overflow in formDelStaState macAddr Parameter
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-36823 WRITEUP HIGH
Tenda W20E 15.11.0.6 - Denial of Service via formAddWebAuthUser Buffer Overflow
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVSS 7.5
CVE-2026-39169 WRITEUP HIGH
SEMCMS 5.0 - Unauthenticated Improper Access Control in SEMCMS_copy.php
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
CVSS 7.5
CVE-2026-39170 WRITEUP MEDIUM
SemCms 5.0 - Cross-Site Request Forgery via /admin/semcms_user.php
SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.
CVSS 6.3
CVE-2026-44716 WRITEUP HIGH
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1.2.0, a path traversal vulnerability exists in Pipecat's development runner (src/pipecat/runner/run.py). When the runner is started with the --folder flag, it exposes a GET /files/{filename:path} download endpoint. The filename path parameter is concatenated directly onto args.folder with no containment check. Starlette normalises literal ../ sequences in URLs, but %2F-encoded slashes bypass this normalisation: the path parameter is URL-decoded after routing, so ..%2F..%2Fetc%2Fpasswd resolves to a path two levels above args.folder. An attacker with network access to the runner can read any file the pipecat process has permission to access — including SSH private keys, credentials, and system files — with a single unauthenticated HTTP request. This issue has been patched in version 1.2.0.
CVSS 7.5
CVE-2026-45782 WRITEUP HIGH
Cloud Hypervisor: Use-after-free in virtio-block Async I/O Completion
Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can cause a use-after-free in the cloud-hypervisor process by submitting two virtio-block descriptor chains that reuse the same head_index while asynchronous block I/O is enabled (e.g. io_uring, aio). When the kernel completes the duplicate operation before the original, the completion path frees a bounce buffer that the kernel is still actively reading from or writing to, corrupting the freed memory. This issue has been patched in versions 51.2 and 52.0.
CVE-2026-46411 WRITEUP MEDIUM
FlashMQ: Client can trigger uncaught exception on FlashMQ 1.26.1 and older
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of their write buffer and triggering an internal safe-guard exception. This exception was in a path that was not catchable, and therefore causes a server abort. This issue has been patched in version 1.26.2.
CVSS 6.5