|
2791
|
6.8 |
MEDIUM
Network
|
-
|
-
|
A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.
|
CWE-78
OS Command
|
CVE-2026-32649
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2792
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-32644
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2793
|
8.8 |
HIGH
Network
|
-
|
-
|
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-20766
|
2026-04-28 10:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2794
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-40974
|
2026-04-28 09:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2795
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-27785
|
2026-04-28 09:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2796
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: validate inner IPv4 header length in IPTFS payload
Add validation of the inner IPv4 packet tot_len and ihl fields pa…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-31472
|
2026-04-28 08:28 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2797
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix potential deadlock in cpu hotplug with osnoise
The following sequence may leads deadlock in cpu hotplug:
task1 …
|
CWE-667
Improper Locking
|
CVE-2026-31480
|
2026-04-28 08:17 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2798
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
i2c: designware: amdisp: Fix resume-probe race condition issue
Identified resume-probe race condition in kernel v7.0 with the com…
|
CWE-362
Race Condition
|
CVE-2026-31572
|
2026-04-28 05:33 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2799
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Unlink NV12 planes earlier
unlink_nv12_plane() will clobber parts of the plane state
potentially already set up by plan…
|
NVD-CWE-noinfo
|
CVE-2026-31571
|
2026-04-28 05:33 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2800
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
s390/mm: Add missing secure storage access fixups for donated memory
There are special cases where secure storage access exceptio…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-31568
|
2026-04-28 05:32 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|