|
301
|
7.3 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-50033
|
2026-06-5 00:12 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302
|
- |
|
-
|
-
|
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
New
|
CWE-78
OS Command
|
CVE-2026-49185
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303
|
- |
|
-
|
-
|
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish r…
New
|
CWE-287
Improper Authentication
|
CVE-2026-49186
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304
|
- |
|
-
|
-
|
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
New
|
CWE-200
Information Exposure
|
CVE-2026-49187
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305
|
- |
|
-
|
-
|
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
New
|
CWE-489
Exposure of Data Element to Wrong Session
|
CVE-2026-49188
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306
|
- |
|
-
|
-
|
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-49189
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307
|
- |
|
-
|
-
|
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
New
|
CWE-78
OS Command
|
CVE-2026-49190
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308
|
- |
|
-
|
-
|
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49191
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309
|
- |
|
-
|
-
|
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-49192
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310
|
- |
|
-
|
-
|
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
New
|
CWE-200
Information Exposure
|
CVE-2026-49193
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|