|
741
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
New
|
CWE-78
OS Command
|
CVE-2026-36576
|
2026-06-5 01:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
742
|
- |
|
-
|
-
|
Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads i…
New
|
-
|
CVE-2026-36460
|
2026-06-5 01:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
743
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-33553
|
2026-06-5 01:25 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
744
|
5.4 |
MEDIUM
Network
|
-
|
-
|
LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG pa…
New
|
CWE-436
Interpretation Conflict
|
CVE-2026-40930
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
745
|
- |
|
-
|
-
|
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on eac…
New
|
CWE-772 CWE-775
Missing Release of Resource after Effective Lifetime Missing Release of File Descriptor or Handle after Effective Lifetime
|
CVE-2026-45287
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
746
|
- |
|
-
|
-
|
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via …
New
|
-
|
CVE-2026-35904
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
747
|
- |
|
-
|
-
|
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
New
|
-
|
CVE-2026-35905
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
748
|
9.6 |
CRITICAL
Network
|
-
|
-
|
An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HT…
New
|
CWE-78
OS Command
|
CVE-2026-35906
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
749
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects WriteUp Mo…
New
|
CWE-284 CWE-862
Improper Access Control Missing Authorization
|
CVE-2026-5228
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
750
|
9.9 |
CRITICAL
Network
|
-
|
-
|
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41283
|
2026-06-5 01:21 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|