|
731
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containin…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-49094
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
732
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent po…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-49095
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
733
|
- |
|
-
|
-
|
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation.
This issue affects SAML SSO - Service Provider: from 0.0.0 befor…
New
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-5343
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
734
|
- |
|
-
|
-
|
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users.
This issue affects TFA Basic Plugins…
New
|
CWE-267
Privilege Defined With Unsafe Actions
|
CVE-2026-6816
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
735
|
5.0 |
MEDIUM
Local
|
-
|
-
|
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic lin…
New
|
CWE-59
Link Following
|
CVE-2026-6891
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
736
|
5.0 |
MEDIUM
Local
|
-
|
-
|
Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installat…
New
|
CWE-59
Link Following
|
CVE-2026-6892
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
737
|
- |
|
-
|
-
|
An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RP…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-7480
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
738
|
- |
|
-
|
-
|
Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical m…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-8070
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
739
|
- |
|
-
|
-
|
Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-49195
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
740
|
- |
|
-
|
-
|
The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.
New
|
CWE-77
Command Injection
|
CVE-2026-49196
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|