|
2621
|
- |
|
-
|
-
|
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumptio…
|
-
|
CVE-2026-39829
|
2026-05-22 13:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2622
|
- |
|
-
|
-
|
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as forc…
|
-
|
CVE-2026-39828
|
2026-05-22 13:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2623
|
- |
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerabil…
|
-
|
CVE-2026-9264
|
2026-05-22 11:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2624
|
- |
|
-
|
-
|
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks.
These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-5091
|
2026-05-22 11:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2625
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is copied into a fixed-…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-45250
|
2026-05-22 11:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2626
|
7.7 |
HIGH
Network
|
-
|
-
|
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulat…
|
CWE-22
Path Traversal
|
CVE-2026-34911
|
2026-05-22 11:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2627
|
10.0 |
CRITICAL
Network
|
-
|
-
|
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
|
CWE-20
Improper Input Validation
|
CVE-2026-34910
|
2026-05-22 11:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2628
|
10.0 |
CRITICAL
Network
|
-
|
-
|
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an und…
|
CWE-22
Path Traversal
|
CVE-2026-34909
|
2026-05-22 11:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2629
|
10.0 |
CRITICAL
Network
|
-
|
-
|
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
|
CWE-284
Improper Access Control
|
CVE-2026-34908
|
2026-05-22 11:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2630
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
|
CWE-20
Improper Input Validation
|
CVE-2026-33000
|
2026-05-22 11:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|