CVE-2026-16097High· 8.8▾ TwilightA vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to la…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.5%
0.5% → 0.8%
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90680Critical· 9.9A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207
CVE-2026-86514Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-86509Critical· 9.6A flaw has been found in D-Link DIR-895L A1_102b07
CVE-2026-86318Medium· 5.3A flaw has been found in java-json-tools json-patch up to 1.13
CVE-2026-86296Critical· 10.0A vulnerability was determined in D-Link DIR-822A A_101
CVE-2026-82478High· 7.3A vulnerability was determined in NASA Trick 19.6.0