|
2521
|
7.8 |
HIGH
Local
|
bitdefender
|
napoca
|
The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kernel/handler.c. The handler uses a guest-controlled S…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10047
|
2026-06-9 00:17 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2522
|
7.0 |
HIGH
Local
|
-
|
-
|
Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
|
-
|
CVE-2026-50265
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2523
|
7.5 |
HIGH
Network
|
-
|
-
|
bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-38570
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2524
|
9.8 |
CRITICAL
Network
|
-
|
-
|
GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.
|
CWE-328
Use of Weak Hash
|
CVE-2026-36182
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2525
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot sessi…
|
-
|
CVE-2026-36180
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2526
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers to obtai…
|
CWE-256
Plaintext Storage of a Password
|
CVE-2026-36174
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2527
|
9.8 |
CRITICAL
Network
|
-
|
-
|
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
|
CWE-259
Use of Hard-coded Password
|
CVE-2026-35905
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2528
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via …
|
CWE-284
Improper Access Control
|
CVE-2026-35904
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2529
|
8.4 |
HIGH
Local
|
-
|
-
|
clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-26422
|
2026-06-9 00:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2530
|
3.5 |
LOW
Network
|
-
|
-
|
A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a ma…
|
CWE-74 CWE-80
Injection Basic XSS
|
CVE-2026-11511
|
2026-06-9 00:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|