CVE-2026-10205
A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/s
CVSS
6.3
Medium
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Published: Jun 1, 2026 · Last modified: Jul 22, 2026 · CWE-284 · CWE-434
0.2%EPSS · 30 days0.2%
2026-07-152026-08-12
A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systparam/softlogo/upload.jsp. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-595058.6 HIG—
——0CWE-284: Improper Access Control2hCVE-2026-595018.2 HIG—
——0CWE-284: Improper Access Control2hCVE-2026-133677.8 HIG—
——0IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.15hCVE-2026-599177.8 HIG—
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.7hCVE-2026-599147.8 HIG—
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.7hCVE-2026-659396.8 MED—
——0In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.7h