Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 015

Количество 396 015

nvd логотип

CVE-2026-8827

4 месяца назад

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itself and therefore poses no direct risk in a default installation. However, custom extensions that call this method with untrusted input would expose the site to SQL injection.

EPSS: Низкий
nvd логотип

CVE-2026-88279

14 дней назад

GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-88278

14 дней назад

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-88277

14 дней назад

GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-88276

14 дней назад

GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-88275

14 дней назад

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-88274

14 дней назад

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-88273

14 дней назад

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-88272

14 дней назад

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-88271

14 дней назад

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-88270

14 дней назад

GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-88269

14 дней назад

GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-88268

14 дней назад

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-88265

14 дней назад

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-88264

14 дней назад

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-88263

8 дней назад

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-88262

9 дней назад

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

EPSS: Низкий
nvd логотип

CVE-2026-88261

9 дней назад

Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.

EPSS: Низкий
nvd логотип

CVE-2026-88260

13 дней назад

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).

EPSS: Низкий
nvd логотип

CVE-2026-8825

2 месяца назад

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-8827

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itself and therefore poses no direct risk in a default installation. However, custom extensions that call this method with untrusted input would expose the site to SQL injection.

0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-88279

GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.

CVSS3: 4.9
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88278

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

CVSS3: 9.8
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88277

GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.

CVSS3: 8.8
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88276

GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.

CVSS3: 7.2
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88275

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.

CVSS3: 7.2
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88274

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

CVSS3: 7.2
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88273

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

CVSS3: 7.2
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88272

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

CVSS3: 7.2
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88271

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

CVSS3: 8.8
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88270

GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.

CVSS3: 6.5
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88269

GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.

CVSS3: 6.5
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88268

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

CVSS3: 6.5
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88265

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

CVSS3: 5.6
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88264

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

CVSS3: 5.6
0%
Низкий
14 дней назад
nvd логотип
CVE-2026-88263

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.

CVSS3: 7.5
1%
Низкий
8 дней назад
nvd логотип
CVE-2026-88262

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

0%
Низкий
9 дней назад
nvd логотип
CVE-2026-88261

Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.

0%
Низкий
9 дней назад
nvd логотип
CVE-2026-88260

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).

0%
Низкий
13 дней назад
nvd логотип
CVE-2026-8825

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).

CVSS3: 4.9
0%
Низкий
2 месяца назад

Уязвимостей на страницу