Overview
- Binardat Ltd.
- 10G08-0800GSM Network Switch
24 Feb 2026
Published
27 Feb 2026
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
0.05%
KEV
Description
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows full administrative access to the device.
Statistics
- 1 Post
Last activity: 21 hours ago
Overview
Description
A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the file /goform/SafeEmailFilter of the component httpd. The manipulation of the argument page leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Statistics
- 1 Post
Last activity: 23 hours ago
Overview
Description
A vulnerability was found in UTT HiPER 810G up to 1.7.7-1711. The affected element is the function strcpy of the file /goform/formTaskEdit_ap. The manipulation of the argument txtMin2 results in buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
Statistics
- 1 Post
Last activity: 16 hours ago
Overview
- SolarWinds
- Serv-U
24 Feb 2026
Published
26 Feb 2026
Updated
CVSS v3.1
CRITICAL (9.1)
EPSS
0.02%
KEV
Description
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
Statistics
- 1 Post
Last activity: 13 hours ago
Overview
Description
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.
Statistics
- 1 Post
Last activity: 1 hour ago
Overview
- SWITCH EV
- swtchenergy.com
26 Feb 2026
Published
27 Feb 2026
Updated
CVSS v3.1
CRITICAL (9.4)
EPSS
Pending
KEV
Description
WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sent to the backend. An unauthenticated attacker can connect to the
OCPP WebSocket endpoint using a known or discovered charging station
identifier, then issue or receive OCPP commands as a legitimate charger.
Given that no authentication is required, this can lead to privilege
escalation, unauthorized control of charging infrastructure, and
corruption of charging network data reported to the backend.
Statistics
- 1 Post
Last activity: Last hour
Overview
Description
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Statistics
- 1 Post
Last activity: 16 hours ago
Fediverse
🔎 HIGH severity: Tenda F453 v1.0.0.3 vulnerable to remote buffer overflow (CVE-2026-3398) via /goform/AdvSetWan. Exploit public, RCE possible with no auth. Disable remote admin & monitor for exploits. Patch ASAP. https://radar.offseq.com/threat/cve-2026-3398-buffer-overflow-in-tenda-f453-735bc013 #OffSeq #Vuln #RouterSec
Overview
- Microsoft
- Windows Notepad
10 Feb 2026
Published
27 Feb 2026
Updated
CVSS v3.1
HIGH (7.8)
EPSS
0.10%
KEV
Description
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.
Statistics
- 1 Post
Last activity: 22 hours ago
Overview
- ZoneMinder
- zoneminder
21 Feb 2026
Published
24 Feb 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.03%
KEV
Description
ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within the getNearEvents() function. Event field values (specifically Name and Cause) are stored safely via parameterized queries but are later retrieved and concatenated directly into SQL WHERE clauses without escaping. An authenticated user with Events edit and view permissions can exploit this to execute arbitrary SQL queries.
Statistics
- 1 Post
Last activity: 21 hours ago
Overview
- Intumit
- SmartRobot′s Conversational AI Platform
26 Dec 2024
Published
26 Dec 2024
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
0.38%
KEV
Description
A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.
Statistics
- 1 Post
Last activity: 2 hours ago