|
1941
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-7786
|
2026-06-2 02:07 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1942
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-5768
|
2026-06-2 02:07 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1943
|
4.3 |
MEDIUM
Adjacent
|
-
|
-
|
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.
A logic error in the address…
|
CWE-823
Use of Out-of-range Pointer Offset
|
CVE-2026-34193
|
2026-06-2 02:07 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1944
|
- |
|
-
|
-
|
In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable
remote code execution on Poly Voice products on the Linux p…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-0826
|
2026-06-2 02:07 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1945
|
4.3 |
MEDIUM
Network
|
apache
|
activemq activemq_broker
|
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.
This issue affects Apa…
|
CWE-285
Improper Authorization
|
CVE-2026-46605
|
2026-06-2 02:07 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1946
|
7.5 |
HIGH
Network
|
-
|
-
|
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote a…
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-10056
|
2026-06-2 02:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1947
|
9.1 |
CRITICAL
Network
|
-
|
-
|
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to pr…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-9051
|
2026-06-2 02:06 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1948
|
3.1 |
LOW
Network
|
apache
|
airflow
|
The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated U…
|
CWE-285
Improper Authorization
|
CVE-2026-40963
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1949
|
6.1 |
MEDIUM
Network
|
apache
|
activemq activemq_web
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
The MessageServlet in the ActiveMQ web console API copies …
|
CWE-79
Cross-site Scripting
|
CVE-2026-42253
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1950
|
6.5 |
MEDIUM
Network
|
apache
|
airflow
|
A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be by…
|
CWE-200
Information Exposure
|
CVE-2026-42360
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|