|
561
|
8.1 |
HIGH
Network
|
trendnet
|
tew-821dap_firmware
|
A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_firmware of the component Firmware Update Handler. Executing a manipulation of …
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-7606
|
2026-05-7 05:23 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
562
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix dir separator in SMB1 UNIX mounts
When calling cifs_mount_get_tcon() with SMB1 UNIX mounts,
@cifs_sb->mnt_cifs_f…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31710
|
2026-05-7 05:21 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
563
|
7.5 |
HIGH
Network
|
lobster-world
|
lobster_pro
|
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server a…
Update
|
CWE-611
XXE
|
CVE-2024-13971
|
2026-05-7 05:19 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
564
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb: server: fix active_num_conn leak on transport allocation failure
Commit 77ffbcac4e56 ("smb: server: fix leak of active_num_c…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31711
|
2026-05-7 05:18 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
565
|
8.8 |
HIGH
Network
|
-
|
-
|
Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass extension restricti…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-41938
|
2026-05-7 05:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
566
|
8.1 |
HIGH
Network
|
-
|
-
|
Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and mod…
New
|
CWE-611
XXE
|
CVE-2026-41936
|
2026-05-7 05:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
567
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the pa…
New
|
CWE-209 CWE-1188
Information Exposure Through an Error Message Insecure Default Initialization of Resource
|
CVE-2026-41931
|
2026-05-7 05:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
568
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin con…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-41930
|
2026-05-7 05:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
569
|
- |
|
-
|
-
|
Rejected reason: This CVE is a duplicate of another CVE: CVE-2026-33079.
New
|
-
|
CVE-2026-33441
|
2026-05-7 05:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
570
|
8.3 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: require minimum ACE size in smb_check_perm_dacl()
Both ACE-walk loops in smb_check_perm_dacl() only guard against an
under…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-31712
|
2026-05-7 05:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|