|
1371
|
7.2 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-33392
|
2026-04-21 05:18 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1372
|
- |
|
-
|
-
|
Rejected reason: This CVE id was assigned as a duplicate of CVE-2025-66414.
|
-
|
CVE-2025-11249
|
2026-04-21 04:16 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1373
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creati…
|
CWE-88
Argument Injection
|
CVE-2026-6437
|
2026-04-21 04:05 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1374
|
4.9 |
MEDIUM
Network
|
-
|
-
|
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal
to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized
SSH access when combined with deb…
|
CWE-23
Relative Path Traversal
|
CVE-2026-31927
|
2026-04-21 04:05 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1375
|
7.7 |
HIGH
Local
|
-
|
-
|
Anviz CX7 Firmware is
vulnerable because the application embeds reusable certificate/key
material, enabling decryption of MQTT traffic and potential interaction
with device messaging channels at s…
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-32324
|
2026-04-21 04:05 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1376
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug
configuration details (e.g., SSH/RTTY status), assisting attackers in
reconnaissance against the device.
|
CWE-862
Missing Authorization
|
CVE-2026-32648
|
2026-04-21 04:05 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1377
|
7.5 |
HIGH
Network
|
-
|
-
|
Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable
encryption, causing database credentials to be sent in plaintext and
enabling unauthorized database …
|
CWE-757
Algorithm Downgrade
|
CVE-2026-32650
|
2026-04-21 04:05 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1378
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures
a photo with the front facing camera, exposing visual information about
the deployment environment.
|
CWE-862
Missing Authorization
|
CVE-2026-33093
|
2026-04-21 04:05 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1379
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling
on‑path attackers to sniff credentials and session data, which can be
used to compromise the device.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-33569
|
2026-04-21 04:05 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1380
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be
retrieved without authentication, revealing sensitive operational
imagery.
|
CWE-862
Missing Authorization
|
CVE-2026-35061
|
2026-04-21 04:05 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|