|
351
|
- |
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7.
User…
New
|
CWE-22
Path Traversal
|
CVE-2025-64152
|
2026-06-26 23:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352
|
7.8 |
HIGH
Local
|
mmaitre314
|
picklescan
|
picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-71348
|
2026-06-26 23:46 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353
|
7.5 |
HIGH
Network
|
-
|
-
|
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allo…
New
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-9220
|
2026-06-26 23:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assig…
New
|
CWE-340
Generation of Predictable Numbers or Identifiers
|
CVE-2026-9219
|
2026-06-26 23:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355
|
- |
|
-
|
-
|
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-6731
|
2026-06-26 23:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356
|
- |
|
-
|
-
|
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier…
New
|
CWE-120 CWE-787
Classic Buffer Overflow Out-of-bounds Write
|
CVE-2026-6681
|
2026-06-26 23:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357
|
- |
|
-
|
-
|
A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length o…
New
|
CWE-190 CWE-197 CWE-787
Integer Overflow or Wraparound Numeric Truncation Error Out-of-bounds Write
|
CVE-2026-6679
|
2026-06-26 23:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358
|
- |
|
-
|
-
|
Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-6678
|
2026-06-26 23:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
359
|
- |
|
-
|
-
|
A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to be accepted. This onl…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-6450
|
2026-06-26 23:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
360
|
- |
|
-
|
-
|
Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.
New
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2026-6412
|
2026-06-26 23:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|