|
1251
|
9.1 |
CRITICAL
Network
|
apache
|
wicket
|
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket.
This issue affects Apache Wicket: from 8.…
|
CWE-384
Session Fixation
|
CVE-2026-40010
|
2026-05-7 22:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1252
|
- |
|
-
|
-
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fix…
|
CWE-121 CWE-170
Stack-based Buffer Overflow Improper Null Termination
|
CVE-2026-34464
|
2026-05-7 22:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1253
|
- |
|
-
|
-
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandl…
|
CWE-121 CWE-170
Stack-based Buffer Overflow Improper Null Termination
|
CVE-2026-34462
|
2026-05-7 22:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1254
|
- |
|
-
|
-
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniServer RunSbieCtrl handler contains a stack buffer overflow. The MSGID_SBIE_I…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-34461
|
2026-05-7 22:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1255
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
cifs: some missing initializations on replay
In several places in the code, we have a label to signify
the start of the code wher…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-31693
|
2026-05-7 21:49 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1256
|
6.7 |
MEDIUM
Local
|
mediatek
|
mt6768_firmware mt6789_firmware mt6877_firmware mt6899_firmware mt6989_firmware mt6991_firmware mt6993_firmware mt8196_firmware mt8367_firmware mt8766_firmware mt8768_fi…
|
In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privileg…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-20447
|
2026-05-7 21:43 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1257
|
6.7 |
MEDIUM
Local
|
mediatek
|
mt6765_firmware mt6768_firmware mt6789_firmware mt6877_firmware mt6897_firmware mt6899_firmware mt6989_firmware mt6991_firmware mt6993_firmware mt8367_firmware mt8766_fi…
|
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System priv…
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-20448
|
2026-05-7 21:43 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1258
|
6.5 |
MEDIUM
Adjacent
|
mediatek
|
mt6763_firmware mt6765_firmware mt6767_firmware mt6768_firmware mt6769_firmware mt6771_firmware mt6779_firmware mt6781_firmware mt6783_firmware mt6785_firmware mt6789_fi…
|
In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with n…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-20449
|
2026-05-7 21:43 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1259
|
6.5 |
MEDIUM
Adjacent
|
mediatek
|
mt2735_firmware mt2737_firmware mt6833_firmware mt6835_firmware mt6853_firmware mt6855_firmware mt6858_firmware mt6873_firmware mt6875_firmware mt6877_firmware mt6878_fi…
|
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with…
|
CWE-617
Reachable Assertion
|
CVE-2026-20450
|
2026-05-7 21:42 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1260
|
6.7 |
MEDIUM
Local
|
mediatek
|
mt8115_firmware mt8186_firmware mt8188_firmware mt8196_firmware mt8365_firmware mt8367_firmware mt8370_firmware mt8371_firmware mt8390_firmware mt8391_firmware mt8395_fi…
|
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interacti…
|
CWE-843
Type Confusion
|
CVE-2026-20451
|
2026-05-7 21:42 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|