|
91
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and …
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-26956
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
4.4 |
MEDIUM
Local
|
mercurycom
|
mipc252w_firmware
|
A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-35901
|
2026-05-5 22:41 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
6.2 |
MEDIUM
Local
|
mercurycom
|
mipc252w_firmware
|
The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete…
Update
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-35902
|
2026-05-5 22:40 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
9.8 |
CRITICAL
Network
|
mercurycom
|
mipc252w_firmware
|
MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, …
Update
|
CWE-287
Improper Authentication
|
CVE-2026-35903
|
2026-05-5 22:39 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
7.2 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the component ApplyRestore Endpoint. This manipulatio…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7833
|
2026-05-5 22:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
7.0 |
HIGH
Local
|
-
|
-
|
A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attackin…
New
|
CWE-59 CWE-61
Link Following UNIX Symbolic Link (Symlink) Following
|
CVE-2026-7832
|
2026-05-5 22:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
9.6 |
CRITICAL
Network
|
-
|
-
|
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability e…
New
|
CWE-89
SQL Injection
|
CVE-2026-42087
|
2026-05-5 22:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
8.7 |
HIGH
Network
|
-
|
-
|
Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulner…
New
|
CWE-89
SQL Injection
|
CVE-2026-35228
|
2026-05-5 22:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
5.9 |
MEDIUM
Network
|
-
|
-
|
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under…
New
|
CWE-302
Authentication Bypass by Assumed-Immutable Data
|
CVE-2026-28510
|
2026-05-5 22:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper …
New
|
CWE-91
Blind XPath Injection
|
CVE-2026-27693
|
2026-05-5 22:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|