2026-04-27
2026-04-27 00:16Z
CRIT

CVE-2026-42363 — An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42363

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the c CVSSv3.1 9.3 (CRITICAL)

CWECWE 656TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-27
2026-04-27 00:16Z
HIGH

CVE-2026-33277 — Injection: An OS command Injection issue exists in LogonTracer prior to v2.0.0.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33277

An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 22:17Z
HIGH

CVE-2026-7057 — This manipulation of the argument funcname/funcpara1 causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7057

A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 22:17Z
HIGH

CVE-2026-7056 — Tenda: The manipulation of the argument page results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7056

A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 22:17Z
HIGH

CVE-2026-7055 — The manipulation of the argument menufacturer/Go leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7055

A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 22:17Z
HIGH

CVE-2026-7054 — Executing a manipulation of the argument opttype/usernamewith can lead to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7054

A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usernamewith can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 22:17Z
HIGH

CVE-2026-7053 — Performing a manipulation of the argument page results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7053

A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-26
2026-04-26 22:17Z
HIGH

CVE-2018-25283 — iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25283

iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary code. Attackers can input a crafted payload exceeding 260 bytes through the System Setup interface to overwrite SEH records and execute shellcode with application privileges. CVSSv3.1 8.4 (HIGH)

CWECWE 120TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-26
2026-04-26 22:17Z
HIGH

CVE-2018-25263 — Faleemi: Desktop Software 1.8.2 contains a local buffer overflow vulnerability in the Device alias

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25263

Faleemi Desktop Software 1.8.2 contains a local buffer overflow vulnerability in the Device alias field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Device alias field within the Managing Log interface to execute arbitrary code with calculator proof-of-concept execution. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDFaleemiTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-26
2026-04-26 19:53Z
HIGH

CVE-2026-6786 — Memory: Some of these bugs showed evidence of memory corruption and we presume that with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6786

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. CVSSv3.1 8.1 (HIGH) · EPSS 14th percentile

CWECWE 416CWECWE 125CWECWE 787TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-26
2026-04-26 19:53Z
HIGH

CVE-2026-6785 — Memory: Some of these bugs showed evidence of memory corruption and we presume that with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6785

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. CVSSv3.1 8.1 (HIGH) · EPSS 17th percentile

CWECWE 416CWECWE 125CWECWE 787TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-26
2026-04-26 12:16Z
CRIT

CVE-2026-7037 — The manipulation of the argument pptpPassThru results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7037

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-26
2026-04-26 12:16Z
HIGH

CVE-2026-7035 — Tenda: Executing a manipulation of the argument Go can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7035

A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. Executing a manipulation of the argument Go can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 12:16Z
HIGH

CVE-2026-7034 — Tenda: Performing a manipulation of the argument Go results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7034

A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Performing a manipulation of the argument Go results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 11:16Z
HIGH

CVE-2026-7033 — Such manipulation of the argument menufacturer/Go leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7033

A vulnerability has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Such manipulation of the argument menufacturer/Go leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 11:16Z
HIGH

CVE-2026-7032 — This manipulation of the argument page causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7032

A flaw has been found in Tenda F456 1.0.0.5. Affected is the function SafeEmailFilter of the file /goform/SafeEmailFilter. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 10:16Z
HIGH

CVE-2026-7031 — Tenda: The manipulation of the argument page results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7031

A vulnerability was detected in Tenda F456 1.0.0.5. This impacts the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page results in buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile

CWECWE 120CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 10:16Z
HIGH

CVE-2026-7030 — The manipulation of the argument page leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7030

A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 09:16Z
HIGH

CVE-2026-7029 — Executing a manipulation of the argument menufacturer/Go can lead to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7029

A weakness has been identified in Tenda F456 1.0.0.5. The impacted element is the function fromaddressNat of the file /goform/addressNat. Executing a manipulation of the argument menufacturer/Go can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-26
2026-04-26 05:16Z
HIGH

CVE-2026-7019 — Tenda: The manipulation of the argument menufacturer/Go leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7019

A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-25
2026-04-25 18:16Z
HIGH

CVE-2026-6988 — This manipulation of the argument nextHop causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6988

A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the function formRoute of the file /boaform/formRouting of the component Boa Service. This manipulation of the argument nextHop causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-25
2026-04-25 09:16Z
CRIT

CVE-2026-31685 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31685

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source address and compares it with the low 64 bits of the IPv6 source address. The existing guard only rejects an invalid MAC header when `par->fragoff != 0`. For packets with `par->fragoff == 0`, `eui64_mt6()` can still reach `eth_hdr(skb)` even when the MAC header is not valid. Fix CVSSv3.1 9.4 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-04-25
2026-04-25 09:16Z
CRIT

CVE-2026-31682 — Linux: In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31682

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns->opt[] and assumes that these options are in the linear part of request. Its callers only guarantee that the ICMPv6 header and target address are available, so the option area can still be non-linear. Parsing ns->opt[] in that case can access data past the linear buffer. Linearize request be CVSSv3.1 9.1 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-25
2026-04-25 06:16Z
CRIT

CVE-2026-6951 — Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6951

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-25
2026-04-25 00:00Z
INFO

Monitoring Claude Code/Cowork at scale with OTel in Elastic

Elastic Security Labs·elastic.co

Elastic Security Labs published a technical guide on building observability pipelines for Claude Code and Claude Cowork using OpenTelemetry (OTel) and Elasticsearch. The post covers telemetry schema, gateway deployment architectures (self-managed EDOT collector vs. Elastic Cloud managed OTLP), custom field mappings, ingest pipelines, and security use cases including tool invocation auditing, session reconstruction, permission decision analysis, and correlation with EDR data.

SRFApplicationTACTA0006SRFCloudSWElasticsearchSWClaudeSWOpentelemetryVNDElasticVNDAnthropic
68
Edit Score