|
4141
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Afectada por esta vulnerabilidad es una funcionalidad desconocida del componente Bluetooth. Tal mani…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-4582
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4142
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown functionality of the component Bluetooth Handler. Performing a manipulation result…
|
CWE-287 CWE-294
Improper Authentication Authentication Bypass by Capture-replay
|
CVE-2026-4583
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4143
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Se detectó una vulnerabilidad en Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Afecta a alguna funcionalidad desconocida del componente Gestor de Bluetooth. Realizar una manipulación resulta en omisi…
|
CWE-287 CWE-294
Improper Authentication Authentication Bypass by Capture-replay
|
CVE-2026-4583
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4144
|
3.1 |
LOW
Adjacent
|
-
|
-
|
A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmissi…
|
CWE-310 CWE-319
Cryptographic Issues Cleartext Transmission of Sensitive Information
|
CVE-2026-4584
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4145
|
3.1 |
LOW
Adjacent
|
-
|
-
|
Se ha encontrado una vulnerabilidad en Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Esto afecta a una parte desconocida del componente Gestor de Datos del Titular de la Tarjeta. La ejecución de una …
|
CWE-310 CWE-319
Cryptographic Issues Cleartext Transmission of Sensitive Information
|
CVE-2026-4584
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4146
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4585
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4147
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument cur…
|
CWE-287 CWE-295
Improper Authentication Improper Certificate Validation
|
CVE-2026-4587
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4148
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the componen…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4589
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4149
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en la Plataforma de Gestión Integrada Tiandy Easy7 hasta la versión 7.17.0. Esta vulnerabilidad afecta a código desconocido del archivo /Easy7/apps/WebService/Impo…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4585
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4150
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/server/web…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4586
|
2026-04-25 01:32 |
2026-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|