|
2431
|
- |
|
-
|
-
|
A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic sign…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2026-9037
|
2026-05-30 00:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2432
|
- |
|
-
|
-
|
A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-9038
|
2026-05-30 00:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2433
|
- |
|
-
|
-
|
A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The se…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-9039
|
2026-05-30 00:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2434
|
5.0 |
MEDIUM
Local
|
-
|
-
|
GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-read…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-44972
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2435
|
- |
|
-
|
-
|
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-32996
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2436
|
- |
|
-
|
-
|
A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.
|
CWE-36
Absolute Path Traversal
|
CVE-2026-32997
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2437
|
- |
|
-
|
-
|
This vulnerability in Veeam Service Provider Console allows for remote code execution.
|
CWE-233
Improper Handling of Parameters
|
CVE-2026-32998
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2438
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the aff…
|
CWE-94
Code Injection
|
CVE-2026-32999
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2439
|
- |
|
-
|
-
|
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.
More precise…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9828
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2440
|
- |
|
-
|
-
|
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embe…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-6720
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|