|
1931
|
8.2 |
HIGH
Network
|
-
|
-
|
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verificatio…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-35675
|
2026-05-29 23:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1932
|
6.5 |
MEDIUM
Network
|
apache
|
ignite
|
Relative Path Traversal vulnerability in Apache Ignite REST API.
Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way.
This iss…
|
CWE-23
Relative Path Traversal
|
CVE-2025-48977
|
2026-05-29 23:11 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1933
|
9.8 |
CRITICAL
Network
|
inhandnetworks
|
ir315_firmware ir302_firmware ir615_firmware ir305_firmware
|
A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier…
|
CWE-77
Command Injection
|
CVE-2026-38702
|
2026-05-29 23:09 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1934
|
9.8 |
CRITICAL
Network
|
inhandnetworks
|
ir315_firmware ir302_firmware ir615_firmware ir305_firmware
|
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier…
|
CWE-77
Command Injection
|
CVE-2026-38703
|
2026-05-29 23:09 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1935
|
9.8 |
CRITICAL
Network
|
inhandnetworks
|
ir315_firmware ir302_firmware ir615_firmware ir305_firmware
|
A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier ve…
|
CWE-77
Command Injection
|
CVE-2026-38707
|
2026-05-29 23:08 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1936
|
9.8 |
CRITICAL
Network
|
inhandnetworks
|
ir315_firmware ir302_firmware ir615_firmware ir305_firmware
|
A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlie…
|
CWE-77
Command Injection
|
CVE-2026-38704
|
2026-05-29 23:08 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1937
|
8.6 |
HIGH
Network
|
-
|
-
|
Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt st…
|
CWE-193
Off-by-one Error
|
CVE-2026-49127
|
2026-05-29 23:07 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1938
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF by…
|
CWE-93
CRLF Injection
|
CVE-2026-49130
|
2026-05-29 23:07 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1939
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allow…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-49129
|
2026-05-29 23:07 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1940
|
4.1 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endp…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-10052
|
2026-05-29 23:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|