6.3
CVE-2026-1685 - D-Link DIR-823X Login sub_40AC74 excessive authentication
A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high co…
6.9
CVE-2026-1684 - Free5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of service
A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can be executed remotely. It is advisable to impleme…
5.8
CVE-2025-6723 - Untrusted user data can lead to privilege escalation
Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may interfere with the pipe connection process and exploit the insufficient access restrictions to assume the InSpec execution context, potentially resulti…
6.9
CVE-2026-1683 - Free5GC SMF PFCP handler.go HandlePfcpSessionReportRequest denial of service
A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. Remote exploitation of the attack is possible. Th…
6.9
CVE-2026-1682 - Free5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereferen…
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exp…
7.5
CVE-2024-4027 - Undertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attac…
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.
4.6
CVE-2025-9226 - Stored XSS
Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.
7
CVE-2026-1498 - WatchGuard Firebox LDAP Injection
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to a…
8.4
CVE-2025-13176 - Local privilege escalation in ESET Inspect Connector for Windows
Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.
9.5
CVE-2025-26385 - Metasys product command injection vulnerability could allow remote SQL execution
Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects * Metasys: Application and Data Server (AD…