| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-63382 | Cri | 0.53 | — | 0.01 | Aug 20, 2026 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can… | ||
| CVE-2026-53424 | Cri | 0.59 | — | 0.01 | Aug 20, 2026 | Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose… | ||
| CVE-2026-2334 | Cri | 0.61 | — | 0.01 | Aug 20, 2026 | An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to… | ||
| CVE-2026-77022 | Cri | 0.64 | 9.9 | 0.01 | Aug 20, 2026 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based… | ||
| CVE-2026-71428 | Cri | 0.53 | 9.3 | 0.00 | Aug 20, 2026 | The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host… | ||
| CVE-2026-55642 | — | Cri | 0.57 | 9.8 | 0.01 | Aug 20, 2026 | dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no… | |
| CVE-2026-18265 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw… | ||
| CVE-2026-63039 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0.0 before 2.4.0. … | ||
| CVE-2026-63038 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters. This issue affects Apache InLong: from… | ||
| CVE-2026-63037 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 before 2.4.0. … | ||
| CVE-2026-16926 | Cri | 0.59 | 9.1 | 0.01 | Aug 20, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input. | ||
| CVE-2026-15706 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before… | ||
| CVE-2026-28164 | Cri | 0.62 | 9.6 | 0.00 | Aug 20, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. | ||
| CVE-2026-18482 | Cri | 0.57 | 9.8 | 0.02 | Aug 20, 2026 | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands,… | ||
| CVE-2026-77071 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a… | ||
| CVE-2026-77070 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker who can influence… | ||
| CVE-2026-74018 | Cri | 0.64 | 9.9 | 0.00 | Aug 20, 2026 | Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. | ||
| CVE-2026-74016 | Cri | 0.64 | 9.9 | 0.00 | Aug 20, 2026 | Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. | ||
| CVE-2026-74014 | Cri | 0.64 | 9.9 | 0.00 | Aug 20, 2026 | Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. | ||
| CVE-2026-74001 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | ||
| CVE-2026-73993 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||
| CVE-2026-73992 | Cri | 0.64 | 9.9 | 0.01 | Aug 20, 2026 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | ||
| CVE-2026-68566 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | ||
| CVE-2026-66682 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2026 | Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | ||
| CVE-2026-66680 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | ||
| CVE-2026-66672 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | ||
| CVE-2026-66649 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | ||
| CVE-2026-66609 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | ||
| CVE-2026-66600 | Cri | 0.59 | 9.1 | 0.01 | Aug 20, 2026 | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | ||
| CVE-2026-66593 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | ||
| CVE-2026-66592 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | ||
| CVE-2026-66583 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | ||
| CVE-2025-15689 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2026 | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | ||
| CVE-2025-15688 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | ||
| CVE-2026-11861 | Cri | 0.55 | 9.6 | 0.00 | Aug 20, 2026 | A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name… | ||
| CVE-2026-14950 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access… | |
| CVE-2026-75860 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to… | ||
| CVE-2026-76850 | Cri | 0.57 | 9.8 | 0.01 | Aug 19, 2026 | LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the… | ||
| CVE-2026-76590 | Cri | 0.64 | 9.9 | 0.01 | Aug 19, 2026 | A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow.… | ||
| CVE-2026-76589 | Cri | 0.64 | 9.9 | 0.01 | Aug 19, 2026 | A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and… | ||
| CVE-2026-76404 | Cri | 0.59 | 9.1 | 0.01 | Aug 19, 2026 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which… | ||
| CVE-2026-76312 | Cri | 0.61 | 9.4 | 0.00 | Aug 19, 2026 | In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system… | ||
| CVE-2026-76311 | Cri | 0.61 | 9.4 | 0.00 | Aug 19, 2026 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system… | ||
| CVE-2026-76310 | Cri | 0.61 | 9.4 | 0.00 | Aug 19, 2026 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report… | ||
| CVE-2026-76584 | Cri | 0.64 | 9.9 | 0.01 | Aug 19, 2026 | A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The… | ||
| CVE-2026-75595 | Cri | 0.52 | 9.1 | 0.00 | Aug 19, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header… | ||
| CVE-2026-53548 | Cri | 0.55 | 9.6 | 0.00 | Aug 19, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password… | ||
| CVE-2026-53546 | Cri | 0.55 | 9.6 | 0.00 | Aug 19, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that host without requiring ownership or… | ||
| CVE-2026-53545 | Cri | 0.57 | 9.8 | 0.01 | Aug 19, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend/ssh/tunnel.ts interpolates endpointPort, sourcePort, endpointUsername, and… | ||
| CVE-2026-63722 | Cri | 0.57 | 9.8 | 0.01 | Aug 19, 2026 | ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP… |
- risk 0.53cvss —epss 0.01
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can…
- risk 0.59cvss —epss 0.01
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose…
- risk 0.61cvss —epss 0.01
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to…
- risk 0.64cvss 9.9epss 0.01
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based…
- risk 0.53cvss 9.3epss 0.00
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host…
- risk 0.57cvss 9.8epss 0.01
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no…
- risk 0.64cvss 9.8epss 0.01
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0.0 before 2.4.0. …
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters. This issue affects Apache InLong: from…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 before 2.4.0. …
- risk 0.59cvss 9.1epss 0.01
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
- risk 0.64cvss 9.8epss 0.01
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before…
- risk 0.62cvss 9.6epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
- risk 0.57cvss 9.8epss 0.02
Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands,…
- risk 0.64cvss 9.8epss 0.01
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a…
- risk 0.64cvss 9.8epss 0.01
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker who can influence…
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- risk 0.64cvss 9.9epss 0.01
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
- risk 0.59cvss 9.1epss 0.01
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
- risk 0.55cvss 9.6epss 0.00
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name…
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access…
- risk 0.64cvss 9.8epss 0.01
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to…
- risk 0.57cvss 9.8epss 0.01
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the…
- risk 0.64cvss 9.9epss 0.01
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow.…
- risk 0.64cvss 9.9epss 0.01
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and…
- risk 0.59cvss 9.1epss 0.01
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which…
- risk 0.61cvss 9.4epss 0.00
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system…
- risk 0.61cvss 9.4epss 0.00
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system…
- risk 0.61cvss 9.4epss 0.00
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report…
- risk 0.64cvss 9.9epss 0.01
A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The…
- risk 0.52cvss 9.1epss 0.00
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header…
- risk 0.55cvss 9.6epss 0.00
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password…
- risk 0.55cvss 9.6epss 0.00
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that host without requiring ownership or…
- risk 0.57cvss 9.8epss 0.01
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend/ssh/tunnel.ts interpolates endpointPort, sourcePort, endpointUsername, and…
- risk 0.57cvss 9.8epss 0.01
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP…