|
931
|
- |
|
-
|
-
|
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-50213
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
932
|
- |
|
-
|
-
|
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-50214
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
933
|
- |
|
-
|
-
|
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.
New
|
CWE-200
Information Exposure
|
CVE-2026-50224
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
934
|
- |
|
-
|
-
|
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-50225
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
935
|
- |
|
-
|
-
|
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extra…
New
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-50226
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
936
|
8.2 |
HIGH
Network
|
-
|
-
|
All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. At…
New
|
CWE-89
SQL Injection
|
CVE-2019-25726
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
937
|
9.8 |
CRITICAL
Network
|
-
|
-
|
WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers…
New
|
CWE-22
Path Traversal
|
CVE-2019-25727
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
938
|
8.2 |
HIGH
Network
|
-
|
-
|
Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject …
New
|
CWE-89
SQL Injection
|
CVE-2019-25728
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
939
|
9.8 |
CRITICAL
Network
|
-
|
-
|
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie paramete…
New
|
CWE-352
Origin Validation Error
|
CVE-2019-25729
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
940
|
8.2 |
HIGH
Network
|
-
|
-
|
Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can s…
New
|
CWE-89
SQL Injection
|
CVE-2019-25730
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|