3d ago
2026-06-05 18:17Z
HIGH

CVE-2026-45327 — TinyIce: In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45327

TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the issue by requiring either HTTP Basic auth or a `?password=` query parameter, comparing the supplied password against the per-mount source password (or the `default_source_password` fallback) using bcrypt, hooking into the existing brute-force IP rate-limiter (5 failed attempts per CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDTinyiceTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3d ago
2026-06-05 18:17Z
CRIT

CVE-2026-36500 — An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36500

An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request. CVSSv3.1 9.1 (CRITICAL) · EPSS 16th percentile

CWECWE 22TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-06-05 18:16Z
CRIT

CVE-2025-71318 — NetMan: A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71318

NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any c CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDNetmanTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-06-05 18:16Z
CRIT

CVE-2025-71317 — NetMan: 204 contains a hard-coded backdoor account with the username and password 'eurek' that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71317

NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which due to lax parameter validation can be shortened to /cgi-bin/login.cgi?username=eurek%20eurek) to obtain administrator privileges, allowing them to alter device configuration, enable the telnet/SS CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDNetmanTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-06-05 17:16Z
HIGH

CVE-2025-5088 — Redis: An authenticated Redis session could be used to obtain full root access to all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-5088

An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over plaintext in the present day. TLS support is tracked under RFE1294850. CVSSv3.1 8.3 (HIGH)

CWECWE 269VNDRedisTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-06-05 17:01Z
HIGH

Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum

Metasploit Framework 6.4.136 adds three new modules: Apache ActiveMQ RCE via Jolokia JMX-over-HTTP (CVE-2026-34197), Gogs Git rebase argument injection RCE, and a Windows kernel pointer enumeration post-exploitation module. The release also includes seven enhancements (Kerberos cracking support, payload manager plugin, session defaults, HTTP scanner improvements) and seven bug fixes across multiple modules.

SRFApplicationTACTA0004TACTA0002SRFWebOSWindowsSWMetasploitSWGogsSWApache Activemq
78
Edit Score
3d ago
2026-06-05 16:16Z
CRIT

CVE-2026-9270 — DataDog: DataDog::DogStatsd versions through 0.07 for Perl allow metric injections.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9270

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change the metric name prefix. The send_stats method does not validate the content of the value ($delta variable), allowing attackers to inject metrics, especially from methods that do CVSSv3.1 9.1 (CRITICAL) · EPSS 8th percentile

CWECWE 93CWECWE 150VNDDatadogTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
3d ago
2026-06-05 16:16Z
CRIT

CVE-2026-11362 — DataDog: DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11362

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

CWECWE 93CWECWE 150VNDDatadogTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-06-05 15:16Z
CRIT

CVE-2026-6209 — Access: Improper Access Control, Missing Authorization vulnerability in HAVELSAN Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6209

Improper Access Control, Missing Authorization vulnerability in HAVELSAN Inc. Geographic Tracking System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Geographic Tracking System: before v0.0.2. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862CWECWE 284VNDAccessTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-06-05 15:16Z
CRIT

CVE-2026-6208 — Authorization: bypass through User-Controlled key vulnerability in HAVELSAN Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6208

Authorization bypass through User-Controlled key vulnerability in HAVELSAN Inc. Geographic Tracking System allows Exploitation of Trusted Identifiers. This issue affects Geographic Tracking System: before v0.0.2. CVSSv3.1 9.1 (CRITICAL)

CWECWE 639TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-06-05 15:16Z
CRIT

CVE-2026-6207 — Observable: Geographic Tracking System allows System Footprinting.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6207

Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows System Footprinting. This issue affects Geographic Tracking System: before v0.0.2. CVSSv3.1 9.1 (CRITICAL)

CWECWE 204VNDObservableTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-06-05 15:16Z
HIGH

CVE-2026-48095 — Zip: Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48095

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)1 << (BlockSizeLog + CompressionUnit), and a crafted image with ClusterSizeLog > CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 190VNDZipTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-06-05 15:16Z
CRIT

CVE-2026-10879 — DBI: versions before 1.648 for Perl have a heap overflow when preparsing SQL statements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10879

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 787VNDDbiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-06-05 13:00Z
CRIT

Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis

Bishop Fox published a detailed analysis of an unauthenticated RCE chain affecting Ubiquiti UniFi OS Server (CVE-2026-34908/34909/34910). The chain exploits an authentication gateway bypass via URI normalization divergence, reaches a command-injection sink in the package-update service, and escalates to root via over-privileged sudoers entries. The appliance controls network management, physical access, and identity systems, making root compromise equivalent to full infrastructure takeover.

SRFApplicationTACTA0004TACTA0001TACTA0002SRFNetwork ApplianceSWUnifi OsVNDUbiquitiTYPResearch
92
Edit Score
3d ago
2026-06-05 09:16Z
CRIT

CVE-2026-6274 — Authentication: Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6274

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 287CWECWE 1390TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-06-05 09:16Z
CRIT

CVE-2026-49777 — Validation: Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49777

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.3. No patched version is available - the vendor has applied a fix to an existing release without publishing a new version. While the patch provided by the vendor is valid, releasing it under the existing version number leaves users unable to rel CVSSv3.1 10.0 (CRITICAL)

CWECWE 1284TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
4d ago
2026-06-05 02:17Z
CRIT

CVE-2026-7763 — A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7763

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives t CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4d ago
2026-06-05 02:17Z
CRIT

CVE-2026-7762 — A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7762

A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon or probe response frame containing a malformed S1G Capabilities Information Element (IE element ID 0xD9). The function morse_dot11ah_find_s1g_caps_for_bssid() CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4d ago
2026-06-05 00:17Z
HIGH

CVE-2026-11307 — Use: after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11307

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-06-05 00:17Z
HIGH

CVE-2026-11306 — Use: after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11306

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-06-05 00:17Z
HIGH

CVE-2026-11305 — Use: after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11305

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-06-05 00:17Z
HIGH

CVE-2026-11304 — Use: after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11304

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-06-05 00:17Z
HIGH

CVE-2026-11303 — Use: after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11303

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-06-05 00:17Z
HIGH

CVE-2026-11301 — Inappropriate: implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11301

Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 125VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-06-05 00:17Z
HIGH

CVE-2026-11295 — Inappropriate: implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11295

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score