|
2171
|
7.8 |
HIGH
Local
|
-
|
-
|
A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-25112
|
2026-05-27 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2172
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Valu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9552
|
2026-05-27 00:17 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2173
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9551
|
2026-05-27 00:17 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2174
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWE…
|
CWE-22
Path Traversal
|
CVE-2026-9550
|
2026-05-27 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2175
|
8.5 |
HIGH
Network
|
-
|
-
|
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution charac…
|
CWE-78
OS Command
|
CVE-2026-4480
|
2026-05-27 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2176
|
5.6 |
MEDIUM
Network
|
-
|
-
|
When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to…
|
CWE-89
SQL Injection
|
CVE-2026-48134
|
2026-05-27 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2177
|
8.1 |
HIGH
Network
|
-
|
-
|
The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-48132
|
2026-05-27 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2178
|
8.8 |
HIGH
Network
|
-
|
-
|
luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — …
|
CWE-77
Command Injection
|
CVE-2026-46368
|
2026-05-27 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2179
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-45247
|
2026-05-27 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2180
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason: This candidate is a duplicate of CVE-2026-43918. Notes: All CVE users should reference CVE-2026-439…
|
-
|
CVE-2026-43919
|
2026-05-27 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|