|
551
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
New
|
CWE-912
Hidden Functionality
|
CVE-2026-1952
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
552
|
7.5 |
HIGH
Network
|
-
|
-
|
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
Mitigation can be done by setting max_resul…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-21728
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
553
|
- |
|
-
|
-
|
A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest.
1. Obtain any valid …
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-6272
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
554
|
- |
|
-
|
-
|
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
An authenticated attacker may by…
New
|
CWE-20 CWE-94
Improper Input Validation Code Injection
|
CVE-2026-40466
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
555
|
- |
|
-
|
-
|
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
An authenticated attacker can show malicious content when browsin…
New
|
CWE-79 CWE-915
Cross-site Scripting Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-41043
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
556
|
- |
|
-
|
-
|
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All.
An authenticated attacker can use …
New
|
CWE-20 CWE-94
Improper Input Validation Code Injection
|
CVE-2026-41044
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
557
|
- |
|
-
|
-
|
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-23902
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
558
|
- |
|
-
|
-
|
AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation b…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4313
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
559
|
- |
|
-
|
-
|
P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user accounts, enumerate…
New
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-6043
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
560
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
New
|
CWE-200
Information Exposure
|
CVE-2026-21515
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|