|
511
|
9.9 |
CRITICAL
Network
|
-
|
-
|
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for one table's files, but a crafted namespace or table name can
cause those credentials to work across …
New
|
CWE-20 CWE-917
Improper Input Validation Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-42811
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
512
|
9.9 |
CRITICAL
Network
|
-
|
-
|
In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files belong to the table and which table version to read.
`write.metadata.path` is an optional table …
New
|
CWE-20 CWE-284 CWE-732 CWE-863
Improper Input Validation Improper Access Control Incorrect Permission Assignment for Critical Resource Incorrect Authorization
|
CVE-2026-42812
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
513
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to …
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-7791
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
514
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPU…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7682
|
2026-05-6 04:30 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
515
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the argument pppUserNam…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7683
|
2026-05-6 04:30 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
516
|
8.8 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in Edimax BR-6428nC up to 1.16. This impacts an unknown function of the file /goform/setWAN. Such manipulation of the argument pptpDfGateway leads to buffe…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7684
|
2026-05-6 04:30 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
517
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in Edimax BR-6208AC up to 1.02. Affected is an unknown function of the file /goform/setWAN. Performing a manipulation of the argument pptpDfGateway results in buffer ove…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7685
|
2026-05-6 04:30 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
518
|
3.7 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib.php of the component Online Si…
Update
|
CWE-345 CWE-347
Insufficient Verification of Data Authenticity Improper Verification of Cryptographic Signature
|
CVE-2026-7689
|
2026-05-6 04:30 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
519
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/p…
Update
|
CWE-189 CWE-190
Numeric Errors Integer Overflow or Wraparound
|
CVE-2026-7598
|
2026-05-6 04:29 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
520
|
5.5 |
MEDIUM
Adjacent
|
-
|
-
|
A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injection. The exploit is now public a…
Update
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7608
|
2026-05-6 04:29 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|