A vulnerability described as problematic has been identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of the component Web Management Interface. Such manipulation of the argument nginxDir leads to cross site scripting.
This vulnerability is documented as CVE-2026-2145. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
美国五大科技公司亚马逊、Google、微软、Meta 和甲骨文今年计划在 AI 上投资大约 7000 亿美元,但在可预计的未来 AI 投资获得的回报远低于支出。而在 AI 上的巨额投资已经让整个世界体验到了无处不在的短缺。熟练电工越来越难以找到,非数据中心建筑项目被迫暂停,智能手机价格未来几年会继续上涨,有前景的创新面临资金不足的困境。知名投资人 Roger McNamee 称,自 2022 年中期以来,美国在 AI 领域的投资额可能超过了此前整个科技行业的所有投资总额。苹果上周通知投资者,该公司在采购 iPhone 和 Mac 电脑所需的两种关键芯片上遇到了困难。CEO Tim Cook 不愿意讨论是否会涨价。非 AI 创业公司的融资额降至十年来的最低点。
DKnife is a Linux toolkit used since 2019 to hijack router traffic and deliver malware in cyber-espionage attacks. Cisco Talos found DKnife, a powerful Linux toolkit that threat actors use to spy on and control network traffic through routers and edge devices. It inspects and alters data in transit and installs malware on PCs, phones, […]
A vulnerability marked as critical has been reported in OptiPNG 0.7.7. Affected by this vulnerability is an unknown functionality of the file gifread.c. This manipulation of the argument buffer causes buffer overflow.
This vulnerability is handled as CVE-2023-43907. The attack can only be done within the local network. There is not any exploit available.
A vulnerability marked as problematic has been reported in writercms 1.1.0. The impacted element is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2023-43905. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability described as problematic has been identified in Xolo CMS 0.11. This affects an unknown function. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2023-43906. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as critical has been reported in EMSigner 2.8.7. Affected is an unknown function. The manipulation leads to weak password recovery.
This vulnerability is listed as CVE-2023-43902. The attack must be carried out from within the local network. There is no available exploit.
A vulnerability identified as critical has been detected in EMSigner 2.8.7. This affects an unknown function of the component AdHoc User Creation Form. Performing a manipulation results in improper access controls.
This vulnerability is identified as CVE-2023-43901. The attack can only be performed from the local network. There is not any exploit available.
A vulnerability marked as critical has been reported in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection.
This vulnerability is cataloged as CVE-2026-2083. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in UTT HiPER 810 1.7.4-141218. It has been rated as critical. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injection.
This vulnerability is referenced as CVE-2026-2080. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical was found in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formFireWall of the component Management Interface. The manipulation of the argument GroupName results in buffer overflow.
This vulnerability is reported as CVE-2026-2086. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in Tenda G300-F up to 16.01.14.2. Affected by this issue is the function formSetWanDiag of the component Management Interface. Such manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-25857. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.113/6.12.54/6.17.4. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in state issue.
This vulnerability is known as CVE-2025-40165. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.12.54/6.17.4/6.18-rc1. This impacts the function exec_destroy. Performing a manipulation results in state issue.
This vulnerability is identified as CVE-2025-40166. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.