|
1081
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected (hidden/debug mode).
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-36742
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1082
|
7.2 |
HIGH
Network
|
-
|
-
|
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. A…
|
CWE-77
Command Injection
|
CVE-2026-36741
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1083
|
7.5 |
HIGH
Network
|
-
|
-
|
striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-28344
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1084
|
7.5 |
HIGH
Network
|
-
|
-
|
striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-28343
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1085
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_SmartAudio::loop, AP_SmartAudio…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2024-51395
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1086
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRo…
|
CWE-120 CWE-121
Classic Buffer Overflow Stack-based Buffer Overflow
|
CVE-2024-48519
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1087
|
9.8 |
CRITICAL
Network
|
artica
|
pandora_fms
|
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800
|
CWE-89
SQL Injection
|
CVE-2026-34187
|
2026-05-14 22:05 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1088
|
9.6 |
CRITICAL
Network
|
langflow
|
langflow
|
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). Th…
|
CWE-22
Path Traversal
|
CVE-2026-42048
|
2026-05-14 21:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1089
|
7.5 |
HIGH
Network
|
vercel
|
next.js
|
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorizatio…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-44575
|
2026-05-14 21:38 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1090
|
8.1 |
HIGH
Network
|
vercel
|
next.js
|
Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to au…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-44574
|
2026-05-14 21:37 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|