|
281
|
5.4 |
MEDIUM
Network
|
traccar
|
traccar
|
Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper …
Update
|
CWE-91
Blind XPath Injection
|
CVE-2026-27693
|
2026-05-9 05:04 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
5.4 |
MEDIUM
Network
|
traccar
|
traccar
|
Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver n…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-27694
|
2026-05-9 05:03 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ceph: supply snapshot context in ceph_zero_partial_object()
The ceph_zero_partial_object function was missing proper snapshot
con…
Update
|
NVD-CWE-noinfo
|
CVE-2026-43273
|
2026-05-9 05:01 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Fix possible dereference of uninitialized pointer
There is a pointer head_page in rb_meta_validate_events() which is…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-43272
|
2026-05-9 05:00 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove()
In mtk_mdp_probe(), vpu_get_plat_device() increases the reference
co…
Update
|
NVD-CWE-Other
|
CVE-2026-43270
|
2026-05-9 05:00 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
md-cluster: fix NULL pointer dereference in process_metadata_update
The function process_metadata_update() blindly dereferences t…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-43271
|
2026-05-9 05:00 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
4.6 |
MEDIUM
Network
|
openc3
|
cosmos
|
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-42086
|
2026-05-9 04:54 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
4.3 |
MEDIUM
Network
|
openc3
|
cosmos
|
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in…
Update
|
CWE-23
Relative Path Traversal
|
CVE-2026-42085
|
2026-05-9 04:54 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
8.1 |
HIGH
Network
|
openc3
|
cosmos
|
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionalit…
Update
|
CWE-620
Unverified Password Change
|
CVE-2026-42084
|
2026-05-9 04:54 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
9.6 |
CRITICAL
Network
|
openc3
|
cosmos
|
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability e…
Update
|
CWE-89
SQL Injection
|
CVE-2026-42087
|
2026-05-9 04:53 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|