7.3

CVSS3.1

CVE-2025-33181 -

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.

πŸ“… Published: Feb. 24, 2026, 6:42 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:42 p.m.

8

CVSS3.1

CVE-2025-33180 -

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.

πŸ“… Published: Feb. 24, 2026, 6:41 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:41 p.m.

8

CVSS3.1

CVE-2025-33179 -

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might lead to escalation of privileges.

πŸ“… Published: Feb. 24, 2026, 6:41 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:41 p.m.

8.7

CVSS4.0

CVE-2026-26342 - Tattile Smart+ / Vega / Basic <= 1.181.5 Insufficient Session Token Expiration

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to au…

πŸ“… Published: Feb. 24, 2026, 6:41 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:41 p.m.

9.3

CVSS4.0

CVE-2026-26341 - Tattile Smart+ / Vega / Basic <= 1.181.5 Default Credentials

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain admini…

πŸ“… Published: Feb. 24, 2026, 6:40 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:40 p.m.

8.7

CVSS4.0

CVE-2026-26340 - Tattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticated RTSP Stream Disclosure

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveill…

πŸ“… Published: Feb. 24, 2026, 6:40 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:40 p.m.

7.6

CVSS3.1

CVE-2026-3105 - SQL Injection in Contact Activity API Sorting

SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated a…

πŸ“… Published: Feb. 24, 2026, 6:39 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:39 p.m.

10

CVSS4.0

CVE-2026-26222 - DocLink .NET Remoting Unauthenticated Arbitrary File Read/Write RCE

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmarshalling,…

πŸ“… Published: Feb. 24, 2026, 5:33 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:36 p.m.

0.0

CVE-2026-25603 - Path Traversal vulnerability in Linksys MR9600, Linksys MX4200

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows thatΒ contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context o…

πŸ“… Published: Feb. 24, 2026, 5:14 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:14 p.m.

4.8

CVSS4.0

CVE-2026-27468 - Mastodon may allow unconfirmed FASP to make subscriptions

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/content lifecycle events or to backfill content d…

πŸ“… Published: Feb. 24, 2026, 5:12 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:12 p.m.
Total resulsts: 334557
Page 2 of 33,456
Β« previous page Β» next page
Filters