|
731
|
- |
|
-
|
-
|
Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command.
This issue was fixed…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-35087
|
2026-05-27 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
732
|
6.2 |
MEDIUM
Local
|
-
|
-
|
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface cla…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-23679
|
2026-05-27 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
733
|
4.3 |
MEDIUM
Network
|
traccar
|
traccar
|
Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and th…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-44314
|
2026-05-27 23:02 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
734
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies the caller-supplied timeout to the SOCKS5 negotiat…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47071
|
2026-05-27 22:56 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
735
|
6.1 |
MEDIUM
Network
|
benoitc
|
hackney
|
Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl passes the original request headers unchanged to th…
New
|
CWE-601
Open Redirect
|
CVE-2026-47070
|
2026-05-27 22:55 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
736
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header parser in src/hackney_altsvc.erl does not guarantee fo…
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-47066
|
2026-05-27 22:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
737
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption in three…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47073
|
2026-05-27 22:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
738
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47077
|
2026-05-27 22:53 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
739
|
5.3 |
MEDIUM
Network
|
benoitc
|
hackney
|
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:setcookie/3 function in src/hackney_cookie.erl validat…
New
|
CWE-93
CRLF Injection
|
CVE-2026-47069
|
2026-05-27 22:53 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
740
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts every unrecognized URL scheme to a permanent BEAM…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-47067
|
2026-05-27 22:52 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|