Post

2026-04-05 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2026-35616Fortinet - FortiClientEMSA improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.CVSS3.1: 9.1 - CRITICAL0Exploitation: noneAutomatable: yesTechnical Impact: totalundefinedgithub
CVE-2020-37216Belden - Hirschmann HiOSHirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attackers can send specially crafted UDP EtherNet/IP packets with a length value larger than the actual packet size to render the device inoperable.CVSS3.1: 7.5 - HIGH CVSS4.0: 8.7 - HIGH0 1Exploitation: noneAutomatable: yesTechnical Impact: partialHirschmann HiOS EtherNet/IP Stack Denial of Servicegithub
CVE-2026-22815aio-libs - aiohttpAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.CVSS4.0: 6.9 - MEDIUM CVSS3.1: 7.5 - HIGH0 1 2Exploitation: noneAutomatable: yesTechnical Impact: partialAIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headersgithub
This post is licensed under CC BY 4.0 by the author.