|
301
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-bas…
New
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10063
|
2026-05-30 00:42 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302
|
5.0 |
MEDIUM
Local
|
-
|
-
|
GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-read…
New
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-44972
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303
|
- |
|
-
|
-
|
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-32996
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304
|
- |
|
-
|
-
|
A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.
New
|
CWE-36
Absolute Path Traversal
|
CVE-2026-32997
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305
|
- |
|
-
|
-
|
This vulnerability in Veeam Service Provider Console allows for remote code execution.
New
|
CWE-233
Improper Handling of Parameters
|
CVE-2026-32998
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the aff…
New
|
CWE-94
Code Injection
|
CVE-2026-32999
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307
|
- |
|
-
|
-
|
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.
More precise…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9828
|
2026-05-30 00:39 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308
|
- |
|
-
|
-
|
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embe…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-6720
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309
|
6.5 |
MEDIUM
Network
|
-
|
-
|
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect…
New
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2026-45306
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310
|
8.7 |
HIGH
Network
|
-
|
-
|
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45348
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|