|
1441
|
10.0 |
CRITICAL
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
Update
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-26332
|
2026-05-6 21:24 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1442
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-605l_firmware
|
D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the s…
Update
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42372
|
2026-05-6 21:20 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1443
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-605l_firmware
|
D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the s…
Update
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42373
|
2026-05-6 21:19 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1444
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-600l_firmware
|
D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static…
Update
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42374
|
2026-05-6 21:18 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1445
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-600l_firmware
|
D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static…
Update
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42375
|
2026-05-6 21:17 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1446
|
2.7 |
LOW
Network
|
-
|
-
|
HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling implementation, increasing the …
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2025-62345
|
2026-05-6 21:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1447
|
8.8 |
HIGH
Network
|
-
|
-
|
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized comma…
New
|
CWE-77 CWE-351 CWE-451
Command Injection Insufficient Type Distinction User Interface (UI) Misrepresentation of Critical Information
|
CVE-2025-31951
|
2026-05-6 21:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1448
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Open5GS up to 2.7.7. Impacted is the function udr_nudr_dr_handle_subscription_context of the file /src/udr/nudr-handler.c of the component UDR. The manipulation of the ar…
Update
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-7707
|
2026-05-6 06:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1449
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remote attackers to cause a denial of…
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-37539
|
2026-05-6 05:24 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1450
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Binary_Data_Transfer_DM16 causing a denial of service via crafted CAN fra…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42467
|
2026-05-6 05:24 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|