|
1631
|
4.3 |
MEDIUM
Network
|
-
|
-
|
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to…
|
CWE-344
Use of Invariant Value in Dynamically Changing Context
|
CVE-2026-42961
|
2026-05-14 00:47 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1632
|
8.2 |
HIGH
Network
|
-
|
-
|
nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the librar…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-29972
|
2026-05-14 00:46 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1633
|
6.5 |
MEDIUM
Local
|
-
|
-
|
Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim …
|
CWE-88
Argument Injection
|
CVE-2026-45181
|
2026-05-14 00:46 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1634
|
2.2 |
LOW
Local
|
-
|
-
|
GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let syste…
|
CWE-441
Confused Deputy
|
CVE-2026-45182
|
2026-05-14 00:46 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1635
|
6.5 |
MEDIUM
Local
|
-
|
-
|
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-45184
|
2026-05-14 00:46 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1636
|
8.1 |
HIGH
Network
|
-
|
-
|
Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/s…
|
CWE-78
OS Command
|
CVE-2026-30635
|
2026-05-14 00:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1637
|
8.8 |
HIGH
Network
|
-
|
-
|
EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient…
|
CWE-77
Command Injection
|
CVE-2026-36734
|
2026-05-14 00:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1638
|
7.3 |
HIGH
Network
|
-
|
-
|
An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function
|
CWE-94
Code Injection
|
CVE-2026-37630
|
2026-05-14 00:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1639
|
3.2 |
LOW
Local
|
-
|
-
|
Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-45362
|
2026-05-14 00:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1640
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Hustle: through 7.8.10.1.
|
CWE-862
Missing Authorization
|
CVE-2026-25431
|
2026-05-14 00:46 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|