|
1011
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41050
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1012
|
- |
|
-
|
-
|
The new upstream added a privileged D-Bus
helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the sy…
New
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-25710
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1013
|
- |
|
-
|
-
|
The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c in
malcontent-timerd allows arbitrary users…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-44931
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1014
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-23819
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1015
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environme…
New
|
CWE-78
OS Command
|
CVE-2026-23820
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1016
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Su…
New
|
CWE-78
OS Command
|
CVE-2026-23821
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1017
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an at…
New
|
CWE-776
XML Entity Expansion
|
CVE-2026-23822
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1018
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacke…
New
|
CWE-77
Command Injection
|
CVE-2026-23823
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1019
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network mess…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-23824
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1020
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data…
New
|
-
|
CVE-2025-11159
|
2026-05-14 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|