|
151
|
8.2 |
HIGH
Network
|
-
|
-
|
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, …
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28224
|
2026-04-18 05:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
152
|
5.1 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-34866
|
2026-04-18 04:26 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
153
|
9.1 |
CRITICAL
Network
|
huawei
|
harmonyos
|
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-34865
|
2026-04-18 04:25 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
154
|
5.7 |
MEDIUM
Local
|
huawei
|
harmonyos emui
|
Out-of-bounds write vulnerability in the kernel module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-34855
|
2026-04-18 04:25 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
155
|
5.6 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Double free vulnerability in the multi-mode input system.
Impact: Successful exploitation of this vulnerability may affect availability.
Update
|
CWE-415
Double Free
|
CVE-2026-34867
|
2026-04-18 04:24 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
156
|
3.5 |
LOW
Network
|
heatmiser
|
wifi_thermostat
|
Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious r…
Update
|
CWE-352
Origin Validation Error
|
CVE-2019-25708
|
2026-04-18 04:17 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
157
|
7.1 |
HIGH
Network
|
ebrigade
|
ebrigade
|
eBrigade ERP 4.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can sen…
Update
|
CWE-89
SQL Injection
|
CVE-2019-25707
|
2026-04-18 04:17 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
158
|
7.8 |
HIGH
Local
|
interference-security
|
echo_mirage
|
Echo Mirage 3.1 contains a stack buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized string in the Rules action fiel…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2019-25705
|
2026-04-18 04:16 |
2026-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
159
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creati…
New
|
CWE-88
Argument Injection
|
CVE-2026-6437
|
2026-04-18 04:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
160
|
9.1 |
CRITICAL
Network
|
-
|
-
|
OpenViking prior to commit c7bb167 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration…
New
|
CWE-636
Not Failing Securely ('Failing Open')
|
CVE-2026-40525
|
2026-04-18 04:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|