|
1621
|
6.2 |
MEDIUM
Network
|
-
|
-
|
A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.
A specially crafted network request can lead to a denial of service. An attacker can imperson…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-12488
|
2026-06-25 23:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1622
|
10.0 |
CRITICAL
Network
|
-
|
-
|
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485.
DVRSearch is a service running by default on the IOBox listening for UDP me…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-12846
|
2026-06-25 23:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1623
|
10.0 |
CRITICAL
Network
|
-
|
-
|
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485.
DVRSearch is a service running by default on the IOBox listening for UDP me…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-12847
|
2026-06-25 23:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1624
|
10.0 |
CRITICAL
Network
|
-
|
-
|
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485.
DVRSearch is a service running by default on the IOBox listening for UDP me…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-12848
|
2026-06-25 23:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1625
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker…
|
CWE-78
OS Command
|
CVE-2026-12849
|
2026-06-25 23:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1626
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker…
|
CWE-78
OS Command
|
CVE-2026-12850
|
2026-06-25 23:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1627
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker…
|
CWE-78
OS Command
|
CVE-2026-12851
|
2026-06-25 23:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1628
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified crede…
|
CWE-862
Missing Authorization
|
CVE-2026-57291
|
2026-06-25 23:01 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1629
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentia…
|
CWE-352
Origin Validation Error
|
CVE-2026-57292
|
2026-06-25 23:01 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1630
|
4.3 |
MEDIUM
Network
|
-
|
-
|
An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particul…
|
CWE-862
Missing Authorization
|
CVE-2026-57293
|
2026-06-25 23:01 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|