|
4991
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both…
|
CWE-798 CWE-912
Use of Hard-coded Credentials Hidden Functionality
|
CVE-2026-41446
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4992
|
7.2 |
HIGH
Network
|
-
|
-
|
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
|
CWE-79
Cross-site Scripting
|
CVE-2026-42615
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4993
|
- |
|
-
|
-
|
SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The vulnerability arises from inadequate validation and…
|
CWE-89
SQL Injection
|
CVE-2026-3325
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4994
|
- |
|
-
|
-
|
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unco…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2026-42248
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4995
|
- |
|
-
|
-
|
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the applicat…
|
CWE-22 CWE-494
Path Traversal Download of Code Without Integrity Check
|
CVE-2026-42249
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4996
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-25852
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4997
|
7.8 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-41220
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4998
|
7.8 |
HIGH
Local
|
-
|
-
|
Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) …
|
CWE-123
Write-what-where Condition
|
CVE-2026-41952
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4999
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2025-56534
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5000
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2025-56535
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|