9.8

CVSS3.1

CVE-2026-24118 - VM2 Sandbox Breakout Through __lookupGetter__

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.

πŸ“… Published: May 4, 2026, 4:28 p.m. πŸ”„ Last Modified: May 4, 2026, 6:45 p.m.

9.4

CVSS4.0

CVE-2026-42809 - Apache Polaris: staged table creation could vend storage credentials for unvalidated locations

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation…

πŸ“… Published: May 4, 2026, 4:22 p.m. πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

9.4

CVSS4.0

CVE-2026-42812 - Apache Polaris: No protection on `write.metadata.path`

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to write those metadata files. For a table already registered in …

πŸ“… Published: May 4, 2026, 4:19 p.m. πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

8.7

CVSS4.0

CVE-2026-29514 - NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the en…

πŸ“… Published: May 4, 2026, 4:05 p.m. πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

9.8

CVSS3.1

CVE-2026-42376 - D-Link DIR-456U A1 Hardcoded Telnet Backdoor Credentials

D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username "Alphanetworks" and the static password "whdrv01_dlob_dir456U" read from /etc/config/image_sign. The custom telnet…

πŸ“… Published: May 4, 2026, 4:03 p.m. πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

9.8

CVSS3.1

CVE-2026-42375 - D-Link DIR-600L A1 Hardcoded Telnet Backdoor Credentials

D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir600l" read from /etc/alpha_config/image_sign. The custom telnetd binary a…

πŸ“… Published: May 4, 2026, 4:02 p.m. πŸ”„ Last Modified: May 6, 2026, 12:17 p.m.

9.8

CVSS3.1

CVE-2026-42374 - D-Link DIR-600L B1 Hardcoded Telnet Backdoor Credentials

D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn61_dlwbr_dir600L" read from /etc/alpha_config/image_sign. The custom telnetd binary a…

πŸ“… Published: May 4, 2026, 4 p.m. πŸ”„ Last Modified: May 6, 2026, 12:18 p.m.

9.8

CVSS3.1

CVE-2026-42373 - D-Link DIR-605L B2 Hardcoded Telnet Backdoor Credentials

D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn76_dlwbr_dir605L" read from /etc/alpha_config/image_sign. The custom telnetd bin…

πŸ“… Published: May 4, 2026, 3:57 p.m. πŸ”„ Last Modified: May 6, 2026, 12:19 p.m.

8.8

CVSS3.1

CVE-2026-42372 - D-Link DIR-605L A1 Hardcoded Telnet Backdoor Credentials

D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign. The custom telnetd bin…

πŸ“… Published: May 4, 2026, 3:53 p.m. πŸ”„ Last Modified: May 6, 2026, 12:20 p.m.

8.1

CVSS3.1

CVE-2026-40563 - Apache Atlas: Script injection allows access to unintended data

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data Affect…

πŸ“… Published: May 4, 2026, 3:17 p.m. πŸ”„ Last Modified: May 6, 2026, 1:27 p.m.
Total resulsts: 349182
Page 133 of 34,919
Β« previous page Β» next page
Filters