|
541
|
4.3 |
MEDIUM
Network
|
misp
|
misp
|
A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New Users and New Organisations widgets. In…
Update
|
CWE-200
Information Exposure
|
CVE-2026-10864
|
2026-06-8 21:59 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
542
|
4.9 |
MEDIUM
Network
|
acer
|
connect_m6e_5g_firmware
|
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.
Update
|
CWE-200
Information Exposure
|
CVE-2026-50224
|
2026-06-8 21:58 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
543
|
9.1 |
CRITICAL
Network
|
acer
|
connect_m6e_5g_firmware
|
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-50225
|
2026-06-8 21:58 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
544
|
5.3 |
MEDIUM
Network
|
acer
|
connect_m6e_5g_firmware
|
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extra…
Update
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-50226
|
2026-06-8 21:57 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
545
|
9.8 |
CRITICAL
Network
|
acer
|
connect_m6e_5g_firmware
|
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-50214
|
2026-06-8 21:56 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
546
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2024-56123
|
2026-06-8 19:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
547
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2024-56122
|
2026-06-8 19:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
548
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2024-56121
|
2026-06-8 19:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
549
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2024-56120
|
2026-06-8 19:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
550
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
New
|
-
|
CVE-2026-36229
|
2026-06-7 06:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|