|
1881
|
8.0 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
|
CWE-79
Cross-site Scripting
|
CVE-2025-14773
|
2026-06-5 00:13 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1882
|
7.4 |
HIGH
Adjacent
|
-
|
-
|
Incorrect Authorization vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
|
CWE-863
Incorrect Authorization
|
CVE-2025-14774
|
2026-06-5 00:13 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1883
|
9.8 |
CRITICAL
Network
|
-
|
-
|
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the serialised stream contains a TC_PROXYCLASSDESC (the ma…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-47065
|
2026-06-5 00:13 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1884
|
7.3 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-42061
|
2026-06-5 00:12 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1885
|
7.3 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-44609
|
2026-06-5 00:12 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1886
|
7.3 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-44682
|
2026-06-5 00:12 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1887
|
7.3 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-50033
|
2026-06-5 00:12 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1888
|
- |
|
-
|
-
|
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
|
CWE-78
OS Command
|
CVE-2026-49185
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1889
|
- |
|
-
|
-
|
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish r…
|
CWE-287
Improper Authentication
|
CVE-2026-49186
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1890
|
- |
|
-
|
-
|
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
|
CWE-200
Information Exposure
|
CVE-2026-49187
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|