|
1781
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute…
|
CWE-22
Path Traversal
|
CVE-2026-6968
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1782
|
7.8 |
HIGH
Local
|
-
|
-
|
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTe…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-42171
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1783
|
4.0 |
MEDIUM
Network
|
-
|
-
|
Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2026-42254
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1784
|
7.0 |
HIGH
Local
|
-
|
-
|
Successful exploitation of the race condition vulnerability could allow
an attacker to trigger a kernel heap overflow, potentially leading to local privilege
escalation and granting system-level acce…
|
CWE-362
Race Condition
|
CVE-2026-3006
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1785
|
- |
|
-
|
-
|
An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration fi…
|
CWE-282
Improper Ownership Management
|
CVE-2026-3867
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1786
|
- |
|
-
|
-
|
An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameters in the HTTPS management inter…
|
CWE-130
Improper Handling of Length Parameter Inconsistency
|
CVE-2026-3868
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1787
|
6.6 |
MEDIUM
Local
|
-
|
-
|
Successful exploitation of the
string injection vulnerability could allow an attacker to obtain memory address
information or crash the application.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2026-3008
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1788
|
5.1 |
MEDIUM
Local
|
-
|
-
|
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
|
CWE-197
Numeric Truncation Error
|
CVE-2026-42371
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1789
|
- |
|
-
|
-
|
OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access restrictions, which may lead to account token hijacking and sensitive information …
|
CWE-346
Origin Validation Error
|
CVE-2026-22077
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1790
|
- |
|
-
|
-
|
Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-15626
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|