Aggregator
CVE-2026-5640 | PHPGurukul Online Shopping Portal Project 2.1 Parameter /admin/update-image2.php filename sql injection (EUVD-2026-19209)
Submit #792963: Totolink A7100RU 7.4cu.2313_b20191024 Command Injection [Accepted]
Submit #792962: Totolink A7100RU 7.4cu.2313_b20191024 Command Injection [Accepted]
Submit #792947: Totolink A7100RU 7.4cu.2313_b20191024 Command Injection [Accepted]
Submit #792946: Totolink A7100RU 7.4cu.2313_b20191024 Command Injection [Accepted]
Submit #792945: Totolink A7100RU 7.4cu.2313_b20191024 Command Injection [Accepted]
Submit #792799: Totolink A3300R V17.0.0cu.557_B20221024 OS Command Injection [Duplicate]
Submit #792798: Totolink A3300R V17.0.0cu.557_B20221024 OS Command Injection [Duplicate]
One Username to Rule Them All: The Persistent RCE Shadow Haunting Control Web Panel
A profound architectural frailty has been unearthed within a ubiquitous server management console, permitting an adversary to usurp
The post One Username to Rule Them All: The Persistent RCE Shadow Haunting Control Web Panel appeared first on Penetration Testing Tools.
CVE-2026-5687 | Tenda CX12L 16.03.53.12 /goform/NatStaticSetting fromNatStaticSetting page stack-based overflow
CVE-2026-5686 | Tenda CX12L 16.03.53.12 /goform/RouteStatic fromRouteStatic page stack-based overflow
CVE-2026-5685 | Tenda CX12L 16.03.53.12 /goform/addressNat fromAddressNat page stack-based overflow
CVE-2026-5684 | Tenda CX12L 16.03.53.12 webExcptypemanFilter fromwebExcptypemanFilter page stack-based overflow
Sovereign Control: How “Multi-Layered” Rowhammer Flips Bits to Hijack NVIDIA GPUs
A sophisticated evolution of the venerable Rowhammer assault has unexpectedly yielded ramifications far more profound than previously envisioned.
The post Sovereign Control: How “Multi-Layered” Rowhammer Flips Bits to Hijack NVIDIA GPUs appeared first on Penetration Testing Tools.
CVE-2026-5683 | Tenda CX12L 16.03.53.12 /goform/P2pListFilter fromP2pListFilter page stack-based overflow
The Long Game: How North Korea’s UNC4736 Spent Six Months Infiltrating Drift for a $285M Payday
The recent incursion into the cryptocurrency sanctuary Drift, which culminated in the exfiltration of $285 million, has been
The post The Long Game: How North Korea’s UNC4736 Spent Six Months Infiltrating Drift for a $285M Payday appeared first on Penetration Testing Tools.