|
11
|
8.8 |
HIGH
Network
|
-
|
-
|
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
New
|
CWE-284
Improper Access Control
|
CVE-2026-5786
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
12
|
8.9 |
HIGH
Network
|
-
|
-
|
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-5787
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
13
|
7.0 |
HIGH
Network
|
-
|
-
|
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
New
|
CWE-284
Improper Access Control
|
CVE-2026-5788
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
14
|
7.2 |
HIGH
Network
|
-
|
-
|
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-6973
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
15
|
7.4 |
HIGH
Network
|
-
|
-
|
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-7821
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
16
|
7.2 |
HIGH
Network
|
-
|
-
|
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cann…
New
|
CWE-912
Hidden Functionality
|
CVE-2026-7413
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
17
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or r…
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-7414
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
18
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetr…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-7415
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
19
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activiti…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-36341
|
2026-05-8 03:45 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
20
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanit…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-36387
|
2026-05-8 03:45 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|