NVD CVEs — 本日公開 (11 件)
CVE-2026-16327 7.3 HIGH
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may
CVE-2026-55831 7.5 HIGH
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySe
CVE-2026-55833 7.5 HIGH
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `
CVE-2026-63728 6.3 MEDIUM
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. Attackers can craft malicious report temp
CVE-2026-16329 7.3 HIGH
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be u
CVE-2026-16330 7.3 HIGH
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote e
CVE-2026-16331 7.3 HIGH
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly
CVE-2026-16332 7.3 HIGH
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may b
CVE-2026-16334 6.3 MEDIUM
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might
CVE-2026-63729 6.6 MEDIUM
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file.
GitHub Security Advisories — 本日公開 (20 件)
GHSA-2rpx-m23v-x3h4
LOW
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability...
GHSA-jf22-92mg-7xxh
MEDIUM
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers...
GHSA-hfvv-f4x9-469c
MEDIUM
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown...
GHSA-957w-jr89-h22x
HIGH
A post-authentication command injection vulnerability in the "LogServer" field of the syslog...
GHSA-2vj5-chrh-vh25
MEDIUM
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the...
GHSA-2hmw-28mw-95rf
MEDIUM
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown...
GHSA-97fr-949f-2h6j
MEDIUM
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the...
GHSA-wwqm-cwjr-9577
UNKNOWN
Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote...
GHSA-6ccf-xr2j-ch59
MEDIUM
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown...
GHSA-j5rv-8p72-245q
UNKNOWN
Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to...