Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 614

Количество 331 614

nvd логотип

CVE-2026-22581

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-22580

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-22579

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-22578

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-22577

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
nvd логотип

CVE-2026-22550

7 дней назад

OS command injection vulnerability exists in WRC-X1500GS-B and WRC-X1500GSA-B. A crafted request from a logged-in user may lead to an arbitrary OS command execution.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-22549

5 дней назад

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-22548

5 дней назад

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-22544

около 1 месяца назад

An attacker with a network connection could detect credentials in clear text.

EPSS: Низкий
nvd логотип

CVE-2026-22543

около 1 месяца назад

The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials

EPSS: Низкий
nvd логотип

CVE-2026-22542

около 1 месяца назад

An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.

EPSS: Низкий
nvd логотип

CVE-2026-22541

около 1 месяца назад

The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

EPSS: Низкий
nvd логотип

CVE-2026-22540

около 1 месяца назад

The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

EPSS: Низкий
nvd логотип

CVE-2026-22539

около 1 месяца назад

As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6.

EPSS: Низкий
nvd логотип

CVE-2026-22537

около 1 месяца назад

The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker.

EPSS: Низкий
nvd логотип

CVE-2026-22536

около 1 месяца назад

The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions

EPSS: Низкий
nvd логотип

CVE-2026-22535

около 1 месяца назад

An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications

EPSS: Низкий
nvd логотип

CVE-2026-22522

около 1 месяца назад

Missing Authorization vulnerability in Munir Kamal Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Block Slider: from n/a through 2.2.3.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-22521

около 1 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework allows PHP Local File Inclusion.This issue affects Handmade Framework: from n/a through 3.9.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-22519

около 1 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress allows Stored XSS.This issue affects MediaPress: from n/a through 1.6.2.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22581

Rejected reason: Not used

около 1 месяца назад
nvd логотип
CVE-2026-22580

Rejected reason: Not used

около 1 месяца назад
nvd логотип
CVE-2026-22579

Rejected reason: Not used

около 1 месяца назад
nvd логотип
CVE-2026-22578

Rejected reason: Not used

около 1 месяца назад
nvd логотип
CVE-2026-22577

Rejected reason: Not used

около 1 месяца назад
nvd логотип
CVE-2026-22550

OS command injection vulnerability exists in WRC-X1500GS-B and WRC-X1500GSA-B. A crafted request from a logged-in user may lead to an arbitrary OS command execution.

CVSS3: 7.2
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-22549

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.9
0%
Низкий
5 дней назад
nvd логотип
CVE-2026-22548

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.9
0%
Низкий
5 дней назад
nvd логотип
CVE-2026-22544

An attacker with a network connection could detect credentials in clear text.

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22543

The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22542

An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22541

The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22540

The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22539

As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6.

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22537

The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker.

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22536

The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22535

An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22522

Missing Authorization vulnerability in Munir Kamal Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Block Slider: from n/a through 2.2.3.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22521

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework allows PHP Local File Inclusion.This issue affects Handmade Framework: from n/a through 3.9.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-22519

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress allows Stored XSS.This issue affects MediaPress: from n/a through 1.6.2.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу