Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 13 April 2026
RSS12 vulnerabilities published on 13 April 2026
Severity:
Totolink A7100RU Firmware Upload Function Allows Remote Attack
CVE-2026-6140
A security flaw in the Totolink A7100RU's firmware upload function allows hackers to potentially take control of the device remotely. This could happen if someone with malicious intent sends a special...
8.9
Totolink A7100RU Router: Remote Command Injection Risk
CVE-2026-6139
A vulnerability in the Totolink A7100RU router's CGI Handler can allow hackers to execute unauthorized commands on the device. This flaw is found in the UploadOpenVpnCert function of the /cgi-bin/cste...
8.9
Totolink A7100RU Router: Malicious Commands Can Be Injected Remotely
CVE-2026-6138
A security flaw in Totolink A7100RU routers allows hackers to execute malicious commands remotely. This means that an attacker can potentially take control of your router and disrupt your internet con...
8.9
Tenda F451 Router: Unsecured Password Can Cause System Crash
CVE-2026-6137
The Tenda F451 router's configuration page is not properly validating some user input, which allows an attacker to crash the system. This could lead to a denial of service, making the router unavailab...
7.4
Tenda F451 Router 1.0.0.7: Remote Data Exposure Through Malformed Web Request
CVE-2026-6136
A misconfigured web interface in Tenda F451 routers makes it possible for an attacker to access unauthorized data by sending a manipulated web request. This is particularly concerning because it can b...
7.4
Tenda F451 Router Allows Unauthenticated Remote Code Execution
CVE-2026-6135
An attacker can access and manipulate the Tenda F451 router's settings to potentially take control of the device. This is a serious security concern as the exploit is publicly available and could be u...
7.4
Exploitable SQL Injection in Vehicle Showroom Management System
CVE-2026-6149
A weak point in the Vehicle Showroom Management System (version 1.0) allows hackers to manipulate data by exploiting a vulnerability in the system's booking process. This could allow unauthorized acce...
6.9
Vehicle Showroom Management System 1.0 allows remote data theft via SQL injection
CVE-2026-6148
A vulnerability in the Vehicle Showroom Management System 1.0 allows hackers to access sensitive data remotely. If exploited, this could lead to theft of confidential information. Update to the latest...
6.9
Tushar-2223 Hotel Management System SQL Injection Risk
CVE-2026-6142
An attacker could potentially inject malicious SQL code into the system of Tushar-2223 Hotel Management System, allowing them to access sensitive data or take control of the system. This vulnerability...
6.9
Farion1231 CC-Switch Vulnerability: Cross-Site Policy Bypass
CVE-2026-6143
A security flaw in Farion1231 CC-Switch versions up to 3.12.3 allows remote attackers to bypass security rules and access sensitive data on untrusted websites. This could expose your business to unaut...
5.3
danielmiessler Personal_AI_Infrastructure: Unpatched Code Allows Remote Attackers to Execute Commands
CVE-2026-6141
A security flaw in the Personal_AI_Infrastructure tool allows hackers to execute commands on your system remotely. This means an attacker could gain control over your system and do anything they want....
5.3
Samsung Open Source Escarogt JavaScript can crash due to bad data
CVE-2026-25204
If an attacker sends malicious data to Samsung's Open Source Escarogt JavaScript, it can cause the program to crash, leading to a denial of service. This is a serious issue because it can disrupt norm...
6.2