🟠 CVE-2026-4314 - High (8.8)

The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequest()` method in the Menu Editor module using ...

🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4314/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

🟠 CVE-2026-4535 - High (8.8)

A vulnerability has been found in Tenda FH451 1.0.0.9. This vulnerability affects the function WrlclientSet of the file /goform/WrlclientSet. Such manipulation of the argument GO leads to stack-based buffer overflow. The attack can be launched rem...

🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4535/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

🟠 CVE-2026-4534 - High (8.8)

A flaw has been found in Tenda FH451 1.0.0.9. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. This manipulation of the argument GO causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has...

🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4534/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

🟠 CVE-2026-4552 - High (8.8)

A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can lead to stack-based buffer o...

🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4552/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

CVE Alert: CVE-2026-4546 - Flos Freeware - Notepad2 - RedPacket Security

A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can

RedPacket Security
CVE Alert: CVE-2019-25613 - Echatserver - Easy Chat - RedPacket Security

Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message

RedPacket Security
CVE Alert: CVE-2019-25612 - Admin-Express - Admin-Express - RedPacket Security

Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by

RedPacket Security
CVE Alert: CVE-2019-25611 - skyqinsc - MiniFtp - RedPacket Security

MiniFtp contains a buffer overflow vulnerability in the parseconf_load_setting function that allows local attackers to execute arbitrary code by supplying

RedPacket Security
CVE Alert: CVE-2019-25615 - Lavavosoftware - Lavavo CD Ripper - RedPacket Security

Lavavo CD Ripper 4.20 contains a structured exception handling (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by

RedPacket Security
CVE Alert: CVE-2019-25619 - Ftpshell - FTP Shell Server - RedPacket Security

FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by

RedPacket Security