Vulnerabilities
Vulnerable Software
Security Vulnerabilities
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
CVSS Score
8.7
EPSS Score
0.0
Published
2026-06-04
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
CVSS Score
8.7
EPSS Score
0.001
Published
2026-06-04
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
CVSS Score
8.5
EPSS Score
0.0
Published
2026-06-04
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
CVSS Score
5.9
EPSS Score
0.002
Published
2026-06-04
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
CVSS Score
10.0
EPSS Score
0.001
Published
2026-06-04
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
CVSS Score
8.6
EPSS Score
0.001
Published
2026-06-04
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
CVSS Score
4.9
EPSS Score
0.0
Published
2026-06-04
HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation. The read may disclose adjacent heap contents into the destination SV.
CVSS Score
7.5
EPSS Score
0.0
Published
2026-06-04
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
CVSS Score
6.5
EPSS Score
0.0
Published
2026-06-04
A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack must be initiated from a local position. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The patch is named 13394. To fix this issue, it is recommended to deploy a patch.
CVSS Score
1.1
EPSS Score
0.0
Published
2026-06-04


Contact Us

Shodan ® - All rights reserved