|
1241
|
3.7 |
LOW
Network
|
-
|
-
|
daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or …
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-44546
|
2026-06-5 00:21 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1242
|
7.5 |
HIGH
Network
|
-
|
-
|
Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial o…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-46638
|
2026-06-5 00:21 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1243
|
- |
|
-
|
-
|
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticat…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-7888
|
2026-06-5 00:20 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1244
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection.
This issue affects TeknoPass: f…
|
CWE-89
SQL Injection
|
CVE-2026-4104
|
2026-06-5 00:20 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1245
|
7.5 |
HIGH
Network
|
-
|
-
|
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
|
CWE-200
Information Exposure
|
CVE-2026-41032
|
2026-06-5 00:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1246
|
6.8 |
MEDIUM
Local
|
-
|
-
|
An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to di…
|
-
|
CVE-2026-7764
|
2026-06-5 00:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1247
|
- |
|
-
|
-
|
ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or adm…
|
CWE-79
Cross-site Scripting
|
CVE-2026-47324
|
2026-06-5 00:14 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1248
|
- |
|
-
|
-
|
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for 12 July 2000). The a…
|
CWE-1391
Use of Weak Credentials
|
CVE-2026-47325
|
2026-06-5 00:14 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1249
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-10584
|
2026-06-5 00:13 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1250
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2025-14771
|
2026-06-5 00:13 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|