|
2351
|
7.8 |
HIGH
Local
|
trendmicro
|
apex_one
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different…
|
CWE-346
Origin Validation Error
|
CVE-2026-34929
|
2026-05-22 22:38 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2352
|
7.8 |
HIGH
Local
|
trendmicro
|
apex_one
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different…
|
CWE-346
Origin Validation Error
|
CVE-2026-34928
|
2026-05-22 22:37 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2353
|
7.8 |
HIGH
Local
|
trendmicro
|
apex_one
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to …
|
CWE-346
Origin Validation Error
|
CVE-2026-34927
|
2026-05-22 22:31 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2354
|
6.7 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents…
|
CWE-23
Relative Path Traversal
|
CVE-2026-34926
|
2026-05-22 21:47 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2355
|
9.8 |
CRITICAL
Network
|
apache
|
fory
|
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resol…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-48207
|
2026-05-22 21:40 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2356
|
- |
|
-
|
-
|
STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authen…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-25608
|
2026-05-22 19:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2357
|
- |
|
-
|
-
|
Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.
This issue was fixed in version…
|
CWE-261
Weak Encoding for Password
|
CVE-2026-25607
|
2026-05-22 19:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2358
|
- |
|
-
|
-
|
A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for SQL Injection attacks. It allows an authenticated …
|
CWE-89
SQL Injection
|
CVE-2026-25606
|
2026-05-22 19:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2359
|
7.5 |
HIGH
Network
|
-
|
-
|
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly…
|
CWE-862
Missing Authorization
|
CVE-2026-9011
|
2026-05-22 18:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2360
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.1. This is due …
|
CWE-862
Missing Authorization
|
CVE-2026-8692
|
2026-05-22 18:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|