Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-39197

CVE-2026-39197_CVE-2026-39197

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted req...

n/a n/a n/a CVE
HIGH 8.4 CVE-2026-39118

CVE-2026-39118_CVE-2026-39118

An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restric...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2026-38065

CVE-2026-38065_CVE-2026-38065

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2026-38064

CVE-2026-38064_CVE-2026-38064

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2026-38063

CVE-2026-38063_CVE-2026-38063

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.

Tenda Tenda 5G03 V05.03.02.04 CVE
CRITICAL 9.8 CVE-2026-38062

CVE-2026-38062_CVE-2026-38062

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.

Tenda Tenda 5G03 V05.03.02.04 CVE
CRITICAL 9.8 CVE-2026-38061

CVE-2026-38061_CVE-2026-38061

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

Tenda Tenda 5G03 V05.03.02.04 CVE
CRITICAL 9.8 CVE-2026-38060

CVE-2026-38060_CVE-2026-38060

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.

Tenda Tenda 5G03 V05.03.02.04 CVE
MEDIUM 6.1 CVE-2026-37216

CVE-2026-37216_CVE-2026-37216

Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-36521

CVE-2026-36521_CVE-2026-36521

PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.

n/a n/a n/a CVE