๐จ CVE-2026-36803
Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow in the page parameter of the qossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow in the page parameter of the qossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/PW201A/qossetting at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36806
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formModifyWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formModifyWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formModifyWebAuthUser at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36807
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formAddWebAuthUser at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36809
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteID parameter of the formModifyWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteID parameter of the formModifyWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formModifyWebAuthWhiteUser at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36810
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoUrl parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoUrl parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formPortalAuth at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36811
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picName parameter of the formDelwebAuthPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picName parameter of the formDelwebAuthPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formDelwebAuthPic at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36813
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formCropAndSetWewifiPic at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36815
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSetNetCheckTools function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSetNetCheckTools function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formSetNetCheckTools at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36816
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formAddWewifiWhiteUser at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36817
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W15E/formAddWebAuthWhiteUser at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36818
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W20E/formAddWewifiWhiteUser at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36819
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the fromSetDhcpRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the fromSetDhcpRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W20E/fromSetDhcpRules at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36821
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W20E/formCropAndSetWewifiPic at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36822
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W20E/formDelStaState at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-36823
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
๐@cveNotify
GitHub
SemVulLLM/W20E/formAddWebAuthUser at main ยท xhh0124/SemVulLLM
Contribute to xhh0124/SemVulLLM development by creating an account on GitHub.
๐จ CVE-2026-39169
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
๐@cveNotify
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
๐@cveNotify
Gist
SEMCMS <= 5.0 Unauthenticated Database Backup Export Vulnerability CVE-2026-39169
SEMCMS <= 5.0 Unauthenticated Database Backup Export Vulnerability CVE-2026-39169 - gist:c30caddaa3204d49d82317bb92bffa43
๐จ CVE-2026-39170
SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.
๐@cveNotify
SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.
๐@cveNotify
Gist
SEMCMS <= 5.0 Sensitive Information Disclosure via Hidden Form Fields CVE-2026-39170
SEMCMS <= 5.0 Sensitive Information Disclosure via Hidden Form Fields CVE-2026-39170 - gist:41e01787357416458212dbbfd06c6d73
๐จ CVE-2026-40639
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.
๐@cveNotify
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.
๐@cveNotify
๐จ CVE-2026-8863
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.
๐@cveNotify
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.
๐@cveNotify
www.kb.cert.org
CERT/CC Vulnerability Note VU#616257
Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass
๐จ CVE-2026-11822
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.
๐@cveNotify
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.
๐@cveNotify
๐จ CVE-2026-11824
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.
๐@cveNotify
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.
๐@cveNotify