|
971
|
7.8 |
HIGH
Local
|
dell
|
alienware_command_center
|
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulnerability in the AWCC. A low privileged attacker with local access could potenti…
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-25908
|
2026-04-29 05:12 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
972
|
- |
|
-
|
-
|
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered.
This…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5362
|
2026-04-29 05:11 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
973
|
7.2 |
HIGH
Network
|
-
|
-
|
Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillm…
|
CWE-94
Code Injection
|
CVE-2026-7191
|
2026-04-29 05:11 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
974
|
7.1 |
HIGH
Adjacent
|
-
|
-
|
A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-28747
|
2026-04-29 05:11 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
975
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.
Affected: Spring Boot 4.0.0–4.0.5 (fix …
|
CWE-295
Improper Certificate Validation
|
CVE-2026-40971
|
2026-04-29 05:11 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
976
|
9.8 |
CRITICAL
Network
|
-
|
-
|
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A succ…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-24178
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
977
|
8.8 |
HIGH
Network
|
-
|
-
|
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerabil…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24186
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
978
|
6.5 |
MEDIUM
Network
|
-
|
-
|
NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.
|
CWE-20
Improper Input Validation
|
CVE-2026-24204
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
979
|
8.6 |
HIGH
Network
|
-
|
-
|
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that cause…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-24222
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
980
|
6.3 |
MEDIUM
Local
|
-
|
-
|
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL refere…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24231
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|