Summary
Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.
…
Summary
Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.
The following versions of Xiiaozet LK100W are affected:
- LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|
Summary
Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.
The following versions of All-Line Equipment Company Fuel-Boss are affected:
- Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
- Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
- …
Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the …
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
- CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability …
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.
The following versions of Bendix EC80 Brake ECU are affected:
- EC80ESP+ J1708 Z228999
- EC80ESP+ 6S/6M …
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation.
The following versions of Ebyte NE2-D11 are affected:
- NE2-D11 Firmware FW-9167-0-11