CVE-2021-46354High· 7.5▾ MidnightPoC availableThinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 2.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
16%
Exploit-DB (last check)
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.
thinfinity_virtualui = 2.1.28.0thinfinity_virtualui = 2.1.32.1thinfinity_virtualui = 2.5.26.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-38474Medium· 4.3A website that had permission to access the microphone could record audio without the audio notification being shown
CVE-2026-54504High· 8.8MCP Documentation Server is a local-first document management and semantic search server for AI coding agents
CVE-2021-45420Critical· 9.8Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi
CVE-2024-21626High· 8.6runc is a CLI tool for spawning and running containers on Linux according to the OCI specification
CVE-2026-86551Low· 3.3The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.
CVE-2026-79031Low· 3.1Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page