The product is released with debugging code still enabled or active.
86 vulnerabilities with CWE-489
CVE-2026-41186
MEDIUM
Unauthenticated Go pprof exposure in Calico debug server
CVE-2026-65893
HIGH
CP PLUS EZ-P21 IP Camera <= v4.8.8.1 - Physical Debug Code Execution
CVE-2026-58378
HIGH
Allwinner TV Box TV98 ADB exposed on network
CVSS 8.8
CVE-2026-54799
MEDIUM
Siemens CPCI85 Central Processing/Communication - Active Debug Code
CVSS 6.7
CVE-2026-54798
MEDIUM
Siemens CPCI85 Central Processing/Communication - Active Debug Code
CVSS 6.5
CVE-2026-58191
MEDIUM
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
CVSS 6.5
CVE-2026-59092
HIGH
JuiceFS - Authentication Bypass via pprof and metrics Endpoints
CVSS 7.7
CVE-2026-49188
CRITICAL
Acer Connect M6E 5G Portable WiFi Router - Elevated Root Command Execution via ai_cmd Sockets
CVSS 9.8
CVE-2026-45728
HIGH
Algernon: Single-file mode unconditionally enables debug mode
CVSS 7.5
CVE-2026-9133
HIGH
Arbitrary file read in rabbitmq-aws plugin
CVSS 7.7
CVE-2026-40035
CRITICAL
Unfurl - Werkzeug Debugger Exposure via String Config Parsing
CVSS 9.1
CVE-2026-32662
MEDIUM
Gardyn Cloud API Active Debug Code
CVSS 5.3
CVE-2026-33201
MEDIUM
GREEN HOUSE CO., LTD. Digital Photo Frame GH-WDF10A - Privilege Escalation
CVSS 6.8
CVE-2026-27131
MEDIUM
Sprig Plugin for Craft CMS potentially discloses sensitive information via Sprig Playground
CVSS 5.5
CVE-2025-15017
HIGH
Serial Device Servers - Privilege Escalation
CVE-2025-42872
MEDIUM
SAP NetWeaver Enterprise Portal - XSS
CVSS 6.1
CVE-2025-2486
HIGH
Ubuntu edk2 UEFI firmware - Auth Bypass
CVSS 8.8
CVE-2025-64983
HIGH
Smart Video Doorbell <2.01.078 - RCE
CVSS 8.0
CVE-2025-54660
MEDIUM
Fortinet FortiClientWindows <7.4.3 - Code Injection
CVSS 5.5
CVE-2025-30185
HIGH
Intel UEFI Reference Platforms - DoS/Privilege Escalation
CVSS 7.9
CVE-2025-52663
HIGH
UniFi Talk <1.21.16, <2.21.22, <3.21.26 - RCE
CVSS 7.3
CVE-2025-4106
HIGH
Fireware OS <12.11.2 - Privilege Escalation
CVE-2025-36899
HIGH
Google Android Test/Debugging Code - Privilege Escalation
CVSS 8.4
CVE-2025-21472
MEDIUM
Qualcomm FastConnect and Snapdragon Firmware - Information Disclosure via eSE Debug Log Capture
CVSS 5.5
CVE-2025-7705
MEDIUM
ABB Switch Actuator <All Versions - Code Injection
CVSS 6.8
Details
Vulnerabilities
86