|
1011
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allo…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-14320
|
2026-05-6 04:34 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1012
|
7.2 |
HIGH
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection.
This issue aff…
New
|
CWE-94
Code Injection
|
CVE-2026-3120
|
2026-05-6 04:34 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1013
|
9.8 |
CRITICAL
Network
|
-
|
-
|
D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username "Alphanetworks…
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42376
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1014
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Apache Polaris can issue broad temporary ("vended") storage credentials during
staged
table creation before the effective table location has been validated or
durably reserved.
Those temporary crede…
New
|
CWE-20 CWE-862
Improper Input Validation Missing Authorization
|
CVE-2026-42809
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1015
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Apache Polaris accepts literal `*` characters in namespace and table names. When it
later builds temporary S3 access policies for delegated table access, those
same characters appear to be reused une…
New
|
CWE-20 CWE-116
Improper Input Validation Improper Encoding or Escaping of Output
|
CVE-2026-42810
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1016
|
9.9 |
CRITICAL
Network
|
-
|
-
|
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for one table's files, but a crafted namespace or table name can
cause those credentials to work across …
New
|
CWE-20 CWE-917
Improper Input Validation Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-42811
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1017
|
9.9 |
CRITICAL
Network
|
-
|
-
|
In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files belong to the table and which table version to read.
`write.metadata.path` is an optional table …
New
|
CWE-20 CWE-284 CWE-732 CWE-863
Improper Input Validation Improper Access Control Incorrect Permission Assignment for Critical Resource Incorrect Authorization
|
CVE-2026-42812
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1018
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to …
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-7791
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1019
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPU…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7682
|
2026-05-6 04:30 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1020
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the argument pppUserNam…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7683
|
2026-05-6 04:30 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|