4.4

CVSS3.1

CVE-2026-35901 - Repeated RTSP SETUP Request Causing Session Termination in Mercury MIPC252W

A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the same media track within a single RTSP session. This causes the server to reset the RTSP connection,…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: May 5, 2026, 1:41 p.m.

7.8

CVSS3.1

CVE-2026-31690 - firmware: thead: Fix buffer overflow and use standard endian macros

In the Linux kernel, the following vulnerability has been resolved: firmware: thead: Fix buffer overflow and use standard endian macros Addresses two issues in the TH1520 AON firmware protocol driver: 1. Fix a potential buffer overflow where the code used unsafe pointer arithmetic to access t…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 6:32 p.m.

5.5

CVSS3.1

CVE-2026-31687 - gpio: omap: do not register driver in probe()

In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Commit 11a78b794496 ("ARM: OMAP: MPUIO wake updates") registers the omap_mpuio_driver from omap_mpuio_init(), which is called from omap_gpio_probe(). However, it neither makes sense …

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 7:05 p.m.

9.8

CVSS3.1

CVE-2026-35903 -

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, the device does not verify the Digest response parameter in subsequent RTSP requests within the same…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: May 5, 2026, 1:39 p.m.

5.5

CVSS3.1

CVE-2026-31689 - EDAC/mc: Fix error path ordering in edac_mc_alloc()

In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc() When the mci->pvt_info allocation in edac_mc_alloc() fails, the error path will call put_device() which will end up calling the device's release function. However, the init ord…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 6:33 p.m.

6.1

CVSS3.1

CVE-2026-38936 - Reflected XSS via namecontains Parameter in diskover‑community Public SelectIndices

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 1:30 p.m.

9.8

CVSS3.1

CVE-2026-30352 -

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 9:17 a.m.

7.5

CVSS3.1

CVE-2026-31256 -

A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream1/track2, the device fails to properly validate the Transport header field. When this header is impr…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: May 5, 2026, 1:30 a.m.

9.3

CVSS3.1

CVE-2026-42363 - GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with variou…

πŸ“… Published: April 26, 2026, 11:58 p.m. πŸ”„ Last Modified: April 26, 2026, 11:58 p.m.

8.7

CVSS4.0

CVE-2026-7068 - D-Link DIR-825 nmbd sserver.c NMBD_process buffer overflow

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated within the local network. The exploit is publicly available and might be used. T…

πŸ“… Published: April 26, 2026, 11:45 p.m. πŸ”„ Last Modified: April 26, 2026, 11:45 p.m.
Total resulsts: 349182
Page 253 of 34,919
Β« previous page Β» next page
Filters