|
2151
|
7.5 |
HIGH
Network
|
marked_project
|
marked
|
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab…
|
CWE-400 CWE-674 CWE-835
Uncontrolled Resource Consumption Uncontrolled Recursion Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-41680
|
2026-04-29 04:37 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2152
|
4.3 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing…
|
CWE-284
Improper Access Control
|
CVE-2026-29197
|
2026-04-29 04:34 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2153
|
5.3 |
MEDIUM
Network
|
opentelemetry
|
opentelemetry opentelemetry.api opentelemetry.extensions.propagators
|
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, …
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-40894
|
2026-04-29 04:34 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2154
|
7.5 |
HIGH
Network
|
senselive
|
x3500_firmware
|
A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, iden…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-35064
|
2026-04-29 04:33 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2155
|
9.8 |
CRITICAL
Network
|
senselive
|
x3500_firmware
|
A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rath…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-35503
|
2026-04-29 04:33 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2156
|
5.3 |
MEDIUM
Network
|
senselive
|
x3500_firmware
|
A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-40431
|
2026-04-29 04:33 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2157
|
9.8 |
CRITICAL
Network
|
senselive
|
x3500_firmware
|
A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config appli…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-40620
|
2026-04-29 04:32 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2158
|
9.1 |
CRITICAL
Network
|
senselive
|
x3500_firmware
|
A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By apply…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-27843
|
2026-04-29 04:32 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2159
|
8.1 |
HIGH
Network
|
senselive
|
x3500_firmware
|
A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Because the application do…
|
CWE-352
Origin Validation Error
|
CVE-2026-27841
|
2026-04-29 04:32 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2160
|
5.4 |
MEDIUM
Network
|
senselive
|
x3500_firmware
|
A vulnerability exists in SenseLive
X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requi…
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-25720
|
2026-04-29 04:31 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|