Vulnerabilities
26 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-10768 | Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2026-29780 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to version 2.0.1, the official example script examples/recursively_extract_attachments.py contains a path traversal vulnerability that allows arbitrary file write outside the intended output directory. Attachment filenames extracted from parsed emails are directly used to construct output file paths without any sanitization, allowing an attacker-controlled filename to escape the target directory. This issue has been patched in version 2.0.1. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-28200 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address. Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-41610 | Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext. Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2024-22048 | govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-6341 | Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifier Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2023-47655 | Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi ANAC XML Bandi di Gara.This issue affects ANAC XML Bandi di Gara: Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi ANAC XML Bandi di Gara.This issue affects ANAC XML Bandi di Gara: from n/a through 7.5. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-45956 | An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands. An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-44689 | e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to im e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a victim of a phishing attack. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2023-42189 | Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-3612 | Govee Home app has unprotected access to WebView component which can be opened by any app on the device. Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2022-31215 | In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules for a time period of up to 30 seconds. This affects Goverlan Reach Console before 10.5.1, Reach Server before 3.70.1, and Reach Client Agents before 10.1.11. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2021-43283 | An issue was discovered on Victure WR1200 devices through 1.0.3. An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges. This occurs in the ping and traceroute features. An attacker would thus be able to use this vulnerability to open a reverse shell on the device with root privileges. NVD description · AI analysis pending | 8.8 group max | 5% | PoC ×2 |
| — | |
| CVE-2020-15744 | Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target de Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target device. This issue affects: Victure PC420 firmware version 1.2.2 and prior versions. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2021-34682 | Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature. Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature. NVD description · AI analysis pending | 3.7 | <1% | PoC |
| — | |
| CVE-2020-12717 | The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Blu The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected. NVD description · AI analysis pending | 6.5 | 1% |
| — | ||
| CVE-2019-20456 | Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Comm Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2019-15940 | Victure PC530 devices allow unauthenticated TELNET access as root. Victure PC530 devices allow unauthenticated TELNET access as root. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-15569 | HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java. HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java. NVD description · AI analysis pending | 9.8 | 1% |
| — |