|
3301
|
- |
-
|
-
|
-
|
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or …
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-42321
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3302
|
- |
-
|
-
|
-
|
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset…
|
CWE-862
Missing Authorization
|
CVE-2026-44281
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3303
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external attacker can rebind a domain to the router's intern…
|
CWE-350
Reliance on Reverse DNS Resolution for a Security-Critical Action
|
CVE-2026-36604
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3304
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low number of crafted incomplete HTTP requests, causing a persistent crash that require…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-36605
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3305
|
7.1 |
HIGH
Local
|
-
|
-
|
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mode. An attacker who obtains a backup file can decrypt…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-36606
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3306
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to th…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-36607
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3307
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or local…
|
CWE-441
Confused Deputy
|
CVE-2026-36608
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3308
|
7.3 |
HIGH
Network
|
-
|
-
|
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the same source IP. Combined with the predictable XOR-bas…
|
CWE-327 CWE-341
Use of a Broken or Risky Cryptographic Algorithm Predictable from Observable State
|
CVE-2026-36609
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3309
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allowing man-in-the-mid…
|
CWE-319 CWE-523
Cleartext Transmission of Sensitive Information Unprotected Transport of Credentials
|
CVE-2026-36610
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3310
|
7.3 |
HIGH
Network
|
-
|
-
|
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory t…
|
CWE-200
Information Exposure
|
CVE-2026-36611
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3311
|
6.4 |
MEDIUM
Adjacent
|
-
|
-
|
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-second lockout after 10 attempts).
|
CWE-307 CWE-1188
mproper Restriction of Excessive Authentication Attempts Insecure Default Initialization of Resource
|
CVE-2026-36612
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3312
|
4.3 |
MEDIUM
Adjacent
|
-
|
-
|
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POST requests to undefined paths, exposing server state to una…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-36613
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3313
|
4.3 |
MEDIUM
Adjacent
|
-
|
-
|
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer contents to unauthenticated attackers on the adjacent network.
|
CWE-200
Information Exposure
|
CVE-2026-36615
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3314
|
5.9 |
MEDIUM
Adjacent
|
-
|
-
|
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS test key, and default PSK embedded in the production firmware…
|
CWE-798 CWE-1188
Use of Hard-coded Credentials Insecure Default Initialization of Resource
|
CVE-2026-36616
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3315
|
4.3 |
MEDIUM
Adjacent
|
-
|
-
|
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against kno…
|
CWE-200
Information Exposure
|
CVE-2026-36618
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3316
|
- |
-
|
-
|
-
|
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in HTML output, bypassing the `hid…
|
CWE-200
Information Exposure
|
CVE-2026-40495
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3317
|
- |
-
|
-
|
-
|
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs befo…
|
CWE-601
Open Redirect
|
CVE-2026-43924
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3318
|
- |
-
|
-
|
-
|
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-AP…
|
CWE-204 CWE-307
Response Discrepancy Information Exposure mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-43926
|
2026-06-5 00:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3319
|
7.4 |
HIGH
Local
|
-
|
-
|
A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Disc Java) sandbox can be escaped through a malformed JAR file.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-64390
|
2026-06-5 00:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3320
|
- |
-
|
-
|
-
|
Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing defect information out of bounds for very large defe…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10717
|
2026-06-5 00:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3321
|
- |
-
|
-
|
-
|
Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms allows for writing extra memory describing a range of LBAs to deallocate 16 by…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10718
|
2026-06-5 00:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3322
|
- |
-
|
-
|
-
|
Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing 1 extra byte outside of allocated memory which sets a val…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10719
|
2026-06-5 00:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3323
|
7.8 |
HIGH
Local
|
-
|
-
|
A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into th…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-41859
|
2026-06-5 00:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3324
|
8.2 |
HIGH
Local
|
-
|
-
|
PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uplo…
|
CWE-78
OS Command
|
CVE-2026-41011
|
2026-06-5 00:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3325
|
7.5 |
HIGH
Network
|
-
|
-
|
Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a s…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2026-41858
|
2026-06-5 00:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3326
|
8.8 |
HIGH
Local
|
-
|
-
|
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-co…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2026-41860
|
2026-06-5 00:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3327
|
6.7 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A lo…
|
CWE-78
OS Command
|
CVE-2026-10805
|
2026-06-5 00:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3328
|
8.2 |
HIGH
Local
|
-
|
-
|
ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from…
|
CWE-78
OS Command
|
CVE-2026-41010
|
2026-06-5 00:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3329
|
7.2 |
HIGH
Network
|
-
|
-
|
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being rest…
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-10843
|
2026-06-5 00:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3330
|
9.6 |
CRITICAL
Adjacent
|
-
|
-
|
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting un…
|
CWE-77
Command Injection
|
CVE-2026-8037
|
2026-06-5 00:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3331
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a network-based denial of service vulnerability that allows network-adjacent attackers to repeatedly trigg…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-25721
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3332
|
7.6 |
HIGH
Adjacent
|
-
|
-
|
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and r…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-25722
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3333
|
4.0 |
MEDIUM
Network
|
-
|
-
|
Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by sending specifically crafted n…
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2019-25723
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3334
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of service vulnerability that allows attackers with access to the hospital or Infinit…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-25724
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3335
|
8.2 |
HIGH
Local
|
-
|
-
|
Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow d…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-4478
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3336
|
8.2 |
HIGH
Local
|
-
|
-
|
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-4480
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3337
|
8.2 |
HIGH
Local
|
-
|
-
|
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-4481
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3338
|
8.6 |
HIGH
Network
|
-
|
-
|
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability t…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2022-4992
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3339
|
7.5 |
HIGH
Network
|
-
|
-
|
Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unenc…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-14036
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3340
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise softwa…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2025-15653
|
2026-06-5 00:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3341
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot th…
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2019-25720
|
2026-06-5 00:29 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3342
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers.
This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-10305
|
2026-06-5 00:27 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3343
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.
This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-47306
|
2026-06-5 00:27 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3344
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-47318
|
2026-06-5 00:27 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3345
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-47319
|
2026-06-5 00:27 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3346
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads.
This issue affects rlottie: befo…
|
CWE-674 CWE-824
Uncontrolled Recursion Access of Uninitialized Pointer
|
CVE-2026-47320
|
2026-06-5 00:27 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3347
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks.
This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-49510
|
2026-06-5 00:27 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3348
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8916
|
2026-06-5 00:27 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3349
|
- |
-
|
-
|
-
|
This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker cou…
|
CWE-78
OS Command
|
CVE-2026-45431
|
2026-06-5 00:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3350
|
- |
-
|
-
|
-
|
This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-45432
|
2026-06-5 00:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|