|
2621
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. A…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2025-15645
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2622
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting inc…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2023-7345
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2623
|
6.6 |
MEDIUM
Network
|
-
|
-
|
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly from user-supplied requ…
|
CWE-470
Unsafe Reflection
|
CVE-2026-34216
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2624
|
6.5 |
MEDIUM
Network
|
-
|
-
|
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints without authorization checks, allowing any authenti…
|
CWE-284 CWE-862
Improper Access Control Missing Authorization
|
CVE-2026-34233
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2625
|
- |
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue originating from a Project other than the current on…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34463
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2626
|
- |
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vulnerability where insufficient access control checks in ProjectUsersAddCommand (…
|
CWE-284
Improper Access Control
|
CVE-2026-34390
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2627
|
- |
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization Bypass through the private issue monitoring feature . Using a crafted POST req…
|
CWE-200 CWE-863
Information Exposure Incorrect Authorization
|
CVE-2026-34579
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2628
|
- |
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and download their own attachments from an Issue created by another user even after it b…
|
CWE-200 CWE-281
Information Exposure Improper Preservation of Permissions
|
CVE-2026-34744
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2629
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This is…
|
CWE-284
Improper Access Control
|
CVE-2026-34754
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2630
|
- |
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note's Revisions page after losing access to the parent private issue. Th…
|
CWE-200
Information Exposure
|
CVE-2026-34970
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|