Vulnerabilities
258 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-48850 | PuTTY 0.72 before 0.84 has a double free in RSA KEX. PuTTY 0.72 before 0.84 has a double free in RSA KEX. NVD description · AI analysis pending | 5.9 group max | <1% |
| — | ||
| CVE-2026-31059 | A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitra A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2026-31060 | UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the formGroupConfig function. UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the formGroupConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NVD description · AI analysis pending | 4.5 | <1% | PoC |
| — | |
| CVE-2026-31058 +1 in the same advisory: …31063 | UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of the formConfigDnsFilterGlobal function. UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of the formConfigDnsFilterGlobal function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NVD description · AI analysis pending | 4.5 | <1% | PoC |
| — | |
| CVE-2026-4115 | A vulnerability was detected in PuTTY 0.83. A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic signature. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The real existence of this vulnerability is still doubted at the moment. The patch is identified as af996b5ec27ab79bae3882071b9d6acf16044549. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a patch for the affected product. However, at the moment there is no proof that this flaw might have any real-world impact. NVD description · AI analysis pending | 2.9 | <1% | PoC |
| — | |
| CVE-2026-3815 +1 in the same advisory: …3814 | A weakness has been identified in UTT HiPER 810G up to 1.7.7-1711. A weakness has been identified in UTT HiPER 810G up to 1.7.7-1711. This affects the function strcpy of the file /goform/formApMail. Executing a manipulation can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. NVD description · AI analysis pending | 7.4 | <1% | PoC |
| — | |
| CVE-2026-3700 | A weakness has been identified in UTT HiPER 810G up to 1.7.7-171114. A weakness has been identified in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigDnsFilterGlobal. This manipulation causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. NVD description · AI analysis pending | 7.4 | <1% | PoC |
| — | |
| CVE-2026-27736 | BigBlueButton is an open-source virtual classroom. BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No known workarounds are available. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2026-27704 | The Dart and Flutter SDKs provide software development kits for the Dart programming language. The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior to version 3.41.0, when the pub client (`dart pub` and `flutter pub`) extracts a package in the pub cache, a malicious package archive can have files extracted outside the destination directory in the `PUB_CACHE`. A fix has been landed in commit 26c6985c742593d081f8b58450f463a584a4203a. By normalizing the file path before writing file, the attacker can no longer traverse up via a symlink. This patch is released in Dart 3.11.0 and Flutter 3.41.0.vAll packages on pub.dev have been vetted for this vulnerability. New packages are no longer allowed to contain symlinks. The pub client itself doesn't upload symlinks, but duplicates the linked entry, and has been doing this for years. Those whose dependencies are all from pub.dev, third-party repositories trusted to not contain malicious code, or git dependencies are not affected by this vulnerability. NVD description · AI analysis pending | 6.6 | <1% |
| — | ||
| CVE-2026-3015 | A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/formPolicyRouteConf. Executing a manipulation of the argument GroupName can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. NVD description · AI analysis pending | 7.4 group max | <1% | PoC ×2 |
| — | |
| CVE-2026-2904 +1 in the same advisory: …2935 | A vulnerability was determined in UTT HiPER 810G 1.7.7-171114. A vulnerability was determined in UTT HiPER 810G 1.7.7-171114. This affects the function strcpy of the file /goform/ConfigExceptAli. Executing a manipulation can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. NVD description · AI analysis pending | 7.4 group max | <1% | PoC |
| — | |
| CVE-2026-27466 +1 in the same advisory: …27467 | BigBlueButton is an open-source virtual classroom. BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Denial of Service. The flawed command exposes both ports (3310 and 7357) to the internet. A remote attacker can use this to send complex or large documents to clamd and waste server resources, or shutdown the clamd process. The clamd documentation explicitly warns about exposing this port. Enabling ufw (ubuntu firewall) during install does not help, because Docker routes container traffic through the nat table, which is not managed or restricted by ufw. Rules installed by ufw in the filter table have no effect on docker traffic. In addition, the provided example also mounts /var/bigbluebutton with write permissions into the container, which should not be required. Future vulnerabilities in clamd may allow attackers to manipulate files in that folder. Users are unaffected unless they have opted in to follow the extra instructions from BigBlueButton's documentation. This issue has been fixed in version 3.0.22. NVD description · AI analysis pending | 8.2 group max | <1% | PoC |
| — | |
| CVE-2026-2846 +1 in the same advisory: …2847 | A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of the component Web Management Interface. The manipulation of the argument policyNames leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. NVD description · AI analysis pending | 7.3 | 10% | PoC |
| — | |
| CVE-2025-70998 | UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowing a remote UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowing a remote attacker to gain root access via a crafted script. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2026-2182 +1 in the same advisory: …2188 | A weakness has been identified in UTT 进取 521G 3.1.1-190816. A weakness has been identified in UTT 进取 521G 3.1.1-190816. Affected by this issue is the function doSystem of the file /goform/setSysAdm. Executing a manipulation of the argument passwd1 can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. NVD description · AI analysis pending | 7.3 | 9% | PoC ×2 |
| — | |
| CVE-2026-2118 +1 in the same advisory: …2135 | A vulnerability was determined in UTT HiPER 810 1.7.4-141218. A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation of the argument Isp_Name can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. NVD description · AI analysis pending | 7.3 group max | 4% | PoC ×2 |
| — | |
| CVE-2026-2086 | A vulnerability was detected in UTT HiPER 810G up to 1.7.7-171114. A vulnerability was detected in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formFireWall of the component Management Interface. The manipulation of the argument GroupName results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.4 | <1% | PoC ×2 |
| — | |
| CVE-2026-2080 | A vulnerability has been found in UTT HiPER 810 1.7.4-141218. A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.3 | 10% | PoC ×2 |
| — | |
| CVE-2026-2071 | A vulnerability was found in UTT 进取 520W 1.7.7-180627. A vulnerability was found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formP2PLimitConfig. Performing a manipulation of the argument except results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.4 | <1% | PoC |
| — | |
| CVE-2026-2067 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTimeGroupConfig. The manipulation of the argument year1 leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.4 | <1% | PoC ×2 |
| — | |
| CVE-2026-1162 | A flaw has been found in UTT HiPER 810 1.7.4-141218. A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/setSysAdm. This manipulation of the argument passwd1 causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used. NVD description · AI analysis pending | 8.9 | <1% |
| — | ||
| CVE-2026-1139 | A vulnerability has been found in UTT 进取 520W 1.7.7-180627. A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.4 | <1% | PoC |
| — | |
| CVE-2026-0840 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.4 | 4% | PoC |
| — |