|
1561
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim…
|
CWE-79
Cross-site Scripting
|
CVE-2026-23819
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1562
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environme…
|
CWE-78
OS Command
|
CVE-2026-23820
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1563
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Su…
|
CWE-78
OS Command
|
CVE-2026-23821
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1564
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an at…
|
CWE-776
XML Entity Expansion
|
CVE-2026-23822
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1565
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacke…
|
CWE-77
Command Injection
|
CVE-2026-23823
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1566
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data…
|
-
|
CVE-2025-11159
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1567
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to ce…
|
CWE-36
Absolute Path Traversal
|
CVE-2026-32175
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1568
|
7.3 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
|
CWE-20 CWE-122
Improper Input Validation Heap-based Buffer Overflow
|
CVE-2026-32177
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1569
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2026-32185
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1570
|
7.8 |
HIGH
Local
|
-
|
-
|
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
|
CWE-73
External Control of File Name or Path
|
CVE-2026-32204
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|