9.4

CVSS4.0

CVE-2026-29080 - Rucio SQL Injection in FilterEngine Oracle JSON Path via DID Search API

A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (`GET /dids/<scope>/dids/search`). On Oracle deployments attacker-controlled filter keys and values are inter…

📅 Published: May 6, 2026, 4:44 p.m. 🔄 Last Modified: May 6, 2026, 10:45 p.m.

7.5

CVSS3.1

CVE-2026-23870 - Denial of Service via Crafted HTTP Requests in Meta React Server DOM Packages

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, reac…

📅 Published: May 6, 2026, 4:24 p.m. 🔄 Last Modified: May 7, 2026, 6:15 p.m.

8.4

CVSS4.0

CVE-2026-21661 - AC2000 Uncontrolled Search Path Element

Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.

📅 Published: May 6, 2026, 4:21 p.m. 🔄 Last Modified: May 6, 2026, 7:05 p.m.

8.8

CVSS3.1

CVE-2026-42503 - Accidental binding to INADDR_ANY might lead to RCE in golang.org/x/tools/gopls

gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0.  As a result, users might inadvertently cause gopls to bind 0.0.0.0. This …

📅 Published: May 6, 2026, 4:20 p.m. 🔄 Last Modified: May 7, 2026, 9:25 p.m.

8.8

CVSS3.1

CVE-2026-20034 - Cisco Unity Connection Remote Code Execution Vulnerability

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability…

📅 Published: May 6, 2026, 4:16 p.m. 🔄 Last Modified: May 7, 2026, 6:15 p.m.

7.2

CVSS3.1

CVE-2026-20035 - Cisco Unity Connection Server-Side Request Forgery Vulnerability

A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by…

📅 Published: May 6, 2026, 4:15 p.m. 🔄 Last Modified: May 7, 2026, 6:15 p.m.

7.7

CVSS3.1

CVE-2026-20167 - Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this …

📅 Published: May 6, 2026, 4:15 p.m. 🔄 Last Modified: May 7, 2026, 6:15 p.m.

6.4

CVSS3.1

CVE-2026-20169 - Cisco IoT Field Network Director Command Injection Vulnerability

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is due to insufficient input validation of user-supplied data. A…

📅 Published: May 6, 2026, 4:15 p.m. 🔄 Last Modified: May 7, 2026, 6:15 p.m.

6.5

CVSS3.1

CVE-2026-20168 - Cisco IoT Field Network Director Path Traversal Vulnerability

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker coul…

📅 Published: May 6, 2026, 4:15 p.m. 🔄 Last Modified: May 7, 2026, 6:15 p.m.

4.3

CVSS3.1

CVE-2026-20172 - Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability

A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent. This vuln…

📅 Published: May 6, 2026, 4:15 p.m. 🔄 Last Modified: May 7, 2026, 8:15 p.m.
Total resulsts: 349182
Page 75 of 34,919
« previous page » next page
Filters