|
411
|
8.8 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipul…
New
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-9442
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
412
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing …
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-9441
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
413
|
- |
|
-
|
-
|
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing…
New
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-9274
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
414
|
- |
|
-
|
-
|
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The…
New
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-5223
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
415
|
- |
|
-
|
-
|
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary na…
New
|
CWE-647
Use of Non-Canonical URL Paths for Authorization Decisions
|
CVE-2026-5222
|
2026-05-25 19:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
416
|
- |
|
-
|
-
|
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user t…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-9490
|
2026-05-25 17:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
417
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulat…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-9440
|
2026-05-25 17:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
418
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command injection. It is poss…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-9439
|
2026-05-25 17:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
419
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file courseDel.php. The manipulation of the arg…
New
|
CWE-99
Resource Injection
|
CVE-2026-9438
|
2026-05-25 17:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
420
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlText leads to os command injection. The at…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9437
|
2026-05-25 17:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|