|
911
|
7.5 |
HIGH
Network
|
-
|
-
|
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
New
|
-
|
CVE-2025-71254
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
7.5 |
HIGH
Network
|
-
|
-
|
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
New
|
-
|
CVE-2025-71255
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
7.5 |
HIGH
Network
|
-
|
-
|
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
New
|
-
|
CVE-2025-71256
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
4.4 |
MEDIUM
Local
|
-
|
-
|
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial…
New
|
CWE-193
Off-by-one Error
|
CVE-2026-7572
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
5.0 |
MEDIUM
Network
|
-
|
-
|
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy …
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-7573
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
- |
|
-
|
-
|
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-23926
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
- |
|
-
|
-
|
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle datab…
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-23927
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
- |
|
-
|
-
|
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized acti…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-23928
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
5.2 |
MEDIUM
Local
|
-
|
-
|
There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, privilege escalation and path traver…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-40001
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
6.3 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hard…
New
|
CWE-1241
Use of Predictable Algorithm in Random Number Generator
|
CVE-2026-6420
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|