|
161
|
4.3 |
MEDIUM
Network
|
-
|
-
|
In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.
New
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2023-5872
|
2026-04-16 14:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
8.8 |
HIGH
Network
|
-
|
-
|
In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of confidentiality, i…
New
|
CWE-1242
Inclusion of Undocumented Features or Chicken Bits
|
CVE-2023-3634
|
2026-04-16 14:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
5.9 |
MEDIUM
Network
|
huawei
|
harmonyos
|
Race condition vulnerability in the notification service.
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-362
Race Condition
|
CVE-2026-34850
|
2026-04-16 14:05 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
7.5 |
HIGH
Network
|
huawei
|
harmonyos
|
Race condition vulnerability in the event notification module.
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-362
Race Condition
|
CVE-2026-34851
|
2026-04-16 14:01 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
6.5 |
MEDIUM
Network
|
huawei
|
harmonyos
|
Stack overflow vulnerability in the media platform.
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-34852
|
2026-04-16 13:54 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
7.5 |
HIGH
Network
|
huawei
|
harmonyos emui
|
Permission bypass vulnerability in the LBS module.
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-270
Privilege Context Switching Error
|
CVE-2026-34853
|
2026-04-16 13:52 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
7.5 |
HIGH
Network
|
huawei
|
harmonyos
|
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-362
Race Condition
|
CVE-2026-34856
|
2026-04-16 13:47 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
6.5 |
MEDIUM
Network
|
huawei
|
harmonyos
|
Access control vulnerability in the memo module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
New
|
CWE-284
Improper Access Control
|
CVE-2026-34860
|
2026-04-16 13:45 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions up to, and including, 1.20.32 due to insufficient output escaping in the galler…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5070
|
2026-04-16 13:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient inpu…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4032
|
2026-04-16 13:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|