|
1041
|
7.3 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-44609
|
2026-06-5 00:12 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1042
|
7.3 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-44682
|
2026-06-5 00:12 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1043
|
7.3 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-50033
|
2026-06-5 00:12 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1044
|
- |
|
-
|
-
|
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
|
CWE-78
OS Command
|
CVE-2026-49185
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1045
|
- |
|
-
|
-
|
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish r…
|
CWE-287
Improper Authentication
|
CVE-2026-49186
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1046
|
- |
|
-
|
-
|
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
|
CWE-200
Information Exposure
|
CVE-2026-49187
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1047
|
- |
|
-
|
-
|
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
|
CWE-489
Exposure of Data Element to Wrong Session
|
CVE-2026-49188
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1048
|
- |
|
-
|
-
|
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
|
CWE-269
Improper Privilege Management
|
CVE-2026-49189
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1049
|
- |
|
-
|
-
|
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
|
CWE-78
OS Command
|
CVE-2026-49190
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1050
|
- |
|
-
|
-
|
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
|
CWE-287
Improper Authentication
|
CVE-2026-49191
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|