|
1501
|
8.4 |
HIGH
Network
|
-
|
-
|
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher throu…
New
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2026-25705
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1502
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41050
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1503
|
- |
|
-
|
-
|
The new upstream added a privileged D-Bus
helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the sy…
New
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-25710
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1504
|
- |
|
-
|
-
|
The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c in
malcontent-timerd allows arbitrary users…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-44931
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1505
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-23819
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1506
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environme…
New
|
CWE-78
OS Command
|
CVE-2026-23820
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1507
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Su…
New
|
CWE-78
OS Command
|
CVE-2026-23821
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1508
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an at…
New
|
CWE-776
XML Entity Expansion
|
CVE-2026-23822
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1509
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacke…
New
|
CWE-77
Command Injection
|
CVE-2026-23823
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1510
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data…
New
|
-
|
CVE-2025-11159
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|