|
4081
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet specially crafted to bear a non-valid value in any Boolean field.
|
CWE-241
Improper Handling of Unexpected Data Type
|
CVE-2025-63548
|
2026-05-6 04:39 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4082
|
- |
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessage-deflate compressio…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-39804
|
2026-05-6 04:37 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4083
|
- |
|
-
|
-
|
Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate Content-Length headers.
'Elixir.Bandit.Headers':get_content_length/1 in lib/b…
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-39805
|
2026-05-6 04:37 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4084
|
- |
|
-
|
-
|
Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections.
'Elixir.Bandit.Pipeline':determine_…
|
CWE-807
Reliance on Untrusted Inputs in a Security Decision
|
CVE-2026-39807
|
2026-05-6 04:37 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4085
|
- |
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion.
The fragment reassembly path in 'Elixir.Ba…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-42786
|
2026-05-6 04:37 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4086
|
- |
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 frames.
'Elixir.Bandit.HTTP2.Frame':deserialize/2 i…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-42788
|
2026-05-6 04:37 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4087
|
- |
|
-
|
-
|
3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing paylo…
|
CWE-78
OS Command
|
CVE-2025-13605
|
2026-05-6 04:35 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4088
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allo…
|
CWE-79
Cross-site Scripting
|
CVE-2025-14320
|
2026-05-6 04:34 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4089
|
7.2 |
HIGH
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection.
This issue aff…
|
CWE-94
Code Injection
|
CVE-2026-3120
|
2026-05-6 04:34 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4090
|
9.8 |
CRITICAL
Network
|
-
|
-
|
D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username "Alphanetworks…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42376
|
2026-05-6 04:32 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|