|
1061
|
8.9 |
HIGH
Network
|
-
|
-
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is en…
|
CWE-79
Cross-site Scripting
|
CVE-2026-43984
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1062
|
- |
|
-
|
-
|
unicodedata.normalize() can take excessive CPU time when processing
specially crafted Unicode input containing long runs of combining characters
with alternating Canonical Combining Class values.
Thi…
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-3276
|
2026-06-5 03:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1063
|
7.8 |
HIGH
Local
|
-
|
-
|
Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remot…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25551
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1064
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The serv…
|
CWE-306 CWE-502
Missing Authentication for Critical Function Deserialization of Untrusted Data
|
CVE-2026-25550
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1065
|
9.8 |
CRITICAL
Network
|
-
|
-
|
OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticat…
|
CWE-89
SQL Injection
|
CVE-2026-10880
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1066
|
7.5 |
HIGH
Network
|
-
|
-
|
nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the available versions …
|
CWE-78
OS Command
|
CVE-2026-10796
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1067
|
8.2 |
HIGH
Network
|
-
|
-
|
An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted command to the at_command.asp interface
|
-
|
CVE-2025-69755
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1068
|
7.1 |
HIGH
Network
|
-
|
-
|
The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize user input in SMS messages before storing and displaying the…
|
-
|
CVE-2025-67448
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1069
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does not properly sanitize user input in the IP address …
|
-
|
CVE-2025-67447
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1070
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie…
|
CWE-384
Session Fixation
|
CVE-2025-67446
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|