Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 10 April 2026

RSS

136 vulnerabilities published on 10 April 2026

Severity:
Totolink A7100RU Router Allows Unauthenticated Password Changes
CVE-2026-5997
A flaw in the Totolink A7100RU router's password management system can allow an attacker to change administrator passwords without needing a password. This means an attacker could gain control of the ...
8.9
Totolink A7100RU Router - Remote Command Injection via CGI Handler
CVE-2026-5996
A security flaw in the Totolink A7100RU router's CGI Handler allows an attacker to execute arbitrary system commands over the internet. This could potentially allow an attacker to gain control of the ...
8.9
Totolink A7100RU Router: Remote Command Execution Possible
CVE-2026-5995
Hackers can potentially run unauthorized commands on the Totolink A7100RU router by manipulating a specific setting. This makes the router vulnerable to attacks from anywhere on the internet. Users sh...
8.9
Totolink A7100RU Router Telnet Configuration Can Be Hacked Remotely
CVE-2026-5994
A security issue in the Totolink A7100RU router's configuration tool allows hackers to remotely access and control the device. This means that an attacker can potentially take control of your router a...
8.9
Totolink A7100RU: Malicious commands can be executed remotely
CVE-2026-5993
A vulnerability in the Totolink A7100RU router's web interface allows an attacker to execute malicious commands on the device, potentially giving them control over the router. This could lead to unaut...
8.9
Tenda F451 Software Allows Remote Attack
CVE-2026-5992
A security flaw in the Tenda F451 software version 1.0.0.7 allows a hacker to potentially take control of the device from a remote location. This could happen if the hacker knows how to manipulate the...
7.4
Tenda F451 Router: Remote Code Execution via Stack Overflow
CVE-2026-5991
The Tenda F451 router's configuration page has a bug that can be exploited by a hacker to execute malicious code remotely. This means a hacker could potentially take control of the router. To protect ...
7.4
Tenda F451 Router Can Crash from Malicious Email Filter Input
CVE-2026-5990
A bug in the Tenda F451 router's email filter can cause the device to crash if it receives a specially crafted email. This can happen remotely, and exploit code is now publicly available. Update your ...
7.4
Tenda F451 1.0.0.7: Remote code execution through manipulated page input
CVE-2026-5989
A critical flaw in the Tenda F451 router's page handling code can allow an attacker to execute malicious code on the router. This could potentially allow the attacker to take control of the router. Up...
7.4
Nginx update fixes four security risks: Denial of Service and Code Execution
RLSA-2026:7343
A security update is available for Nginx, a popular web server software. This update fixes four security issues that could allow hackers to crash the server, modify files, or execute malicious code. T...
8.2
Perfmatters Plugin for WordPress Allows Attackers to Delete Server Files
CVE-2026-4351
The Perfmatters plugin for WordPress is insecure, allowing attackers with Subscriber-level access to delete any file on the server. This could cause your website to stop working or behave unexpectedly...
8.1
MagicINFO 9 Server has default permissions that can be exploited
CVE-2026-25203
The MagicINFO 9 Server has a default permission setting that could allow an attacker to gain elevated access to the system. This means that an unauthorized user could potentially get access to sensiti...
7.8
Tutor LMS plugin for WordPress exposes user billing info to attackers
CVE-2026-3360
An attacker can modify any user's billing information by guessing or finding an incomplete order ID. This can happen because the plugin doesn't check if the user making the change is authorized to do ...
7.5
Important: nodejs:24 security update
RLSA-2026:7350
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * nodejs: Nodejs denial of service (CVE-2026...
7.5
Simple IT Discussion Forum 1.0 Allows Unrestricted Database Access
CVE-2026-6004
A security issue in Simple IT Discussion Forum 1.0 allows attackers to access sensitive database information. This could lead to unauthorized changes or theft of data. Update to the latest version of ...
6.9
Webling Plugin for WordPress: Malicious Code Injection Risk
CVE-2026-1263
The Webling plugin for WordPress has a security flaw that allows hackers to inject malicious code into certain areas of the admin dashboard, potentially allowing them to take control of the site. This...
6.4
JeecgBoot 3.9.1 - Unauthorized Access to Announcement System
CVE-2026-5999
A vulnerability in JeecgBoot's announcement system can allow an attacker to access unauthorized areas. This could potentially lead to sensitive information being viewed or modified without permission....
5.3
wolfSSL TLS 1.3 PQC KeyShare Processing Can Leak Sensitive Data
CVE-2026-5460
The wolfSSL TLS 1.3 implementation for post-quantum cryptography has a bug that allows sensitive data to be leaked. This is a security risk because it could potentially expose confidential information...
6.3
wolfSSL: Experimental Certificate Parsing Problem
CVE-2026-5393
A specific input can cause wolfSSL to access memory it shouldn't. When using wolfSSL with certain experimental features enabled, a crafted certificate can cause the software to accidentally read memor...
6.3
Royal WordPress Backup & Restore Plugin: Admin Clickjacking Attack Possible
CVE-2026-4305
The Royal WordPress Backup & Restore Plugin is at risk of being exploited if an administrator is tricked into clicking on a malicious link. Attackers could inject malicious scripts into the plugin's i...
6.1
WP-Optimize Plugin Allows Untrusted Users to Access Admin Functions
CVE-2026-2712
The WP-Optimize plugin for WordPress has a security issue that lets users with basic access levels perform actions reserved for administrators, such as accessing logs, deleting files, and modifying se...
5.4
Zhayujie ChatGPT on WeChat CowAgent Allows Remote File Access
CVE-2026-5998
A critical issue has been discovered in the CowAgent component of ChatGPT on WeChat, which could allow an attacker to access files on your system. This means that a hacker could potentially access sen...
5.5
WooCommerce Customer Reviews plugin allows anyone to post reviews
CVE-2026-4664
This plugin for WooCommerce has a security weakness that lets anyone submit, modify, or inject fake reviews for any product without needing a password. This can happen because the plugin doesn't prope...
5.3
Code-projects Online Library Management System SQL Database Backup File Handler Leaks Data
CVE-2026-6000
An unknown function in the SQL Database Backup File Handler of Code-projects Online Library Management System 1.0 can leak sensitive information. This could happen if an attacker remotely exploits a p...
2.1
UsersWP plugin allows attackers to delete sensitive user data
CVE-2026-4977
The UsersWP plugin for WordPress is affected by a security flaw that allows attackers with subscriber-level access to delete sensitive user information. This can happen when an attacker uses the plugi...
4.3