7.6

CVSS3.1

CVE-2026-41904 - FreeScout Stored XSS vulnerability in mailbox auto-reply: payload reaches every customer's email cl…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply message. The payload is rendered unescaped in the auto-reply email sent to every customer who contac…

📅 Published: May 7, 2026, 6:05 p.m. 🔄 Last Modified: May 7, 2026, 8:30 p.m.

9.1

CVSS3.1

CVE-2026-41902 - FreeScout's user invitation hash never expires: permanent unauthenticated account takeover if invit…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration check — the hash remains valid indefinitely until …

📅 Published: May 7, 2026, 6:03 p.m. 🔄 Last Modified: May 7, 2026, 8:30 p.m.

5.4

CVSS3.1

CVE-2026-41903 - FreeScout IDOR Vulnerability: PERM_EDIT_USERS allows modifying any user's notification subscription…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permission (intended for general user-profile editing) can read and modify the notification subscriptions of any other user, including admins, by sending a…

📅 Published: May 7, 2026, 6:02 p.m. 🔄 Last Modified: May 7, 2026, 8:30 p.m.

5.3

CVSS4.0

CVE-2026-8081 - router-for-me CLIProxyAPI api_tools.go server-side request forgery

A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploi…

📅 Published: May 7, 2026, 6 p.m. 🔄 Last Modified: May 7, 2026, 6:08 p.m.

9.8

CVSS3.1

CVE-2026-7415 - Open MQTT orchestration without read/write ACLs in Yarbo robot firmware

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization o…

📅 Published: May 7, 2026, 4:11 p.m. 🔄 Last Modified: May 7, 2026, 4:11 p.m.

9.8

CVSS3.1

CVE-2026-7414 - Hardcoded credentials in Yarbo robot firmware

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone …

📅 Published: May 7, 2026, 4:10 p.m. 🔄 Last Modified: May 7, 2026, 5:15 p.m.

7.2

CVSS3.1

CVE-2026-7413 - Persistent undocumented backdoor access in Yarbo robot

A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.

📅 Published: May 7, 2026, 4:09 p.m. 🔄 Last Modified: May 7, 2026, 4:09 p.m.

8.9

CVSS3.1

CVE-2026-5787 - Certificate Validation Flaw Enables Impersonation of Sentry Hosts in Ivanti Endpoint Manager Mobile

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

📅 Published: May 7, 2026, 3:36 p.m. 🔄 Last Modified: May 7, 2026, 8:12 p.m.

7

CVSS3.1

CVE-2026-5788 - Remote Unauthorized Method Invocation via Improper Access Control in Ivanti EPMM

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

📅 Published: May 7, 2026, 3:29 p.m. 🔄 Last Modified: May 7, 2026, 8:11 p.m.

7.4

CVSS3.1

CVE-2026-7821 - Improper Certificate Validation Enabling Unauthorized Device Enrollment in Ivanti EPMM

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of t…

📅 Published: May 7, 2026, 3:26 p.m. 🔄 Last Modified: May 7, 2026, 8:09 p.m.
Total resulsts: 349182
Page 43 of 34,919
« previous page » next page
Filters