9.8

CVSS3.1

CVE-2026-35903 -

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, the device does not verify the Digest response parameter in subsequent RTSP requests within the sameโ€ฆ

๐Ÿ“… Published: April 27, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 1:39 p.m.

5.5

CVSS3.1

CVE-2026-31689 - EDAC/mc: Fix error path ordering in edac_mc_alloc()

In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc() When the mci->pvt_info allocation in edac_mc_alloc() fails, the error path will call put_device() which will end up calling the device's release function. However, the init ordโ€ฆ

๐Ÿ“… Published: April 27, 2026, midnight ๐Ÿ”„ Last Modified: May 6, 2026, 6:33 p.m.

6.1

CVSS3.1

CVE-2026-38936 - Reflected XSS via namecontains Parameter in diskoverโ€‘community Public SelectIndices

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

๐Ÿ“… Published: April 27, 2026, midnight ๐Ÿ”„ Last Modified: April 28, 2026, 1:30 p.m.

9.8

CVSS3.1

CVE-2026-30352 -

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

๐Ÿ“… Published: April 27, 2026, midnight ๐Ÿ”„ Last Modified: April 28, 2026, 9:17 a.m.

7.5

CVSS3.1

CVE-2026-31256 -

A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream1/track2, the device fails to properly validate the Transport header field. When this header is imprโ€ฆ

๐Ÿ“… Published: April 27, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 1:30 a.m.

9.3

CVSS3.1

CVE-2026-42363 - GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with variouโ€ฆ

๐Ÿ“… Published: April 26, 2026, 11:58 p.m. ๐Ÿ”„ Last Modified: April 26, 2026, 11:58 p.m.

8.7

CVSS4.0

CVE-2026-7068 - D-Link DIR-825 nmbd sserver.c NMBD_process buffer overflow

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated within the local network. The exploit is publicly available and might be used. Tโ€ฆ

๐Ÿ“… Published: April 26, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: April 26, 2026, 11:45 p.m.

6.9

CVSS4.0

CVE-2026-7067 - D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection

A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been publโ€ฆ

๐Ÿ“… Published: April 26, 2026, 11:30 p.m. ๐Ÿ”„ Last Modified: April 26, 2026, 11:30 p.m.

6.9

CVSS4.0

CVE-2026-7066 - choieastsea simple-openstack-mcp server.py exec_openstack os command injection

A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function exec_openstack of the file server.py. The manipulation results in os command injection. It is possible to launch the attack remotely. The exploit has beโ€ฆ

๐Ÿ“… Published: April 26, 2026, 11:15 p.m. ๐Ÿ”„ Last Modified: April 26, 2026, 11:15 p.m.

6.9

CVSS4.0

CVE-2026-7065 - BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-side request โ€ฆ

A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the component Remote Upload API. The manipulation of the argument url leads to server-side request forgery. โ€ฆ

๐Ÿ“… Published: April 26, 2026, 11 p.m. ๐Ÿ”„ Last Modified: April 26, 2026, 11 p.m.
Total resulsts: 348618
Page 197 of 34,862
ยซ previous page ยป next page
Filters