CVE-2026-10764High· 8.7▾ TwilightInformation disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.
BVMS >= 4.5 <= 12.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103055High· 7.5AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set
CVE-2026-102241Low· 2.7A vulnerability was determined in Netcore NAP930 0.1.241010.141410
CVE-2026-82929Medium· 6.3mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation
CVE-2026-75553Low· 2.4Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.
CVE-2026-75558Medium· 5.3The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device
CVE-2026-79762Medium· 5.5Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities