|
5301
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due to insufficient escaping on…
|
CWE-89
SQL Injection
|
CVE-2026-8685
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5302
|
7.5 |
HIGH
Network
|
-
|
-
|
The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the u…
|
CWE-89
SQL Injection
|
CVE-2026-9010
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5303
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal o…
|
CWE-200
Information Exposure
|
CVE-2026-5075
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5304
|
8.8 |
HIGH
Network
|
-
|
-
|
The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes it possible for aut…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-7522
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5305
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This mak…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-7637
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5306
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insuffi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2955
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5307
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insuffic…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-6566
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5308
|
8.8 |
HIGH
Network
|
-
|
-
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. Th…
|
CWE-862
Missing Authorization
|
CVE-2026-5200
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5309
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in versions up to and including 0.…
|
CWE-352
Origin Validation Error
|
CVE-2026-6405
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5310
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for una…
|
CWE-200
Information Exposure
|
CVE-2026-6728
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5311
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS.
This issue affects Visualizer: from n/a before 4.0.0.
|
CWE-79
Cross-site Scripting
|
CVE-2026-24573
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5312
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpBookingly: from n/a through 1.2.9.
|
CWE-862
Missing Authorization
|
CVE-2026-27405
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5313
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Image Photo Gallery F…
|
CWE-862
Missing Authorization
|
CVE-2026-27424
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5314
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection.
This issue affects YITH WooCom…
|
CWE-89
SQL Injection
|
CVE-2026-42383
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5315
|
5.0 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affect…
|
CWE-862
Missing Authorization
|
CVE-2026-45443
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5316
|
8.1 |
HIGH
Network
|
-
|
-
|
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authentica…
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-47107
|
2026-05-20 22:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5317
|
7.3 |
HIGH
Network
|
-
|
-
|
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-26462
|
2026-05-20 22:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5318
|
- |
-
|
-
|
-
|
A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.
|
CWE-94
Code Injection
|
CVE-2026-6902
|
2026-05-20 16:16 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5319
|
- |
-
|
-
|
-
|
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start…
|
CWE-284 CWE-427 CWE-829
Improper Access Control Uncontrolled Search Path Element Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-7373
|
2026-05-20 08:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5320
|
9.1 |
CRITICAL
Network
|
adenhq
|
hive
|
A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the component Delete Request Handler. Perfor…
|
CWE-22
Path Traversal
|
CVE-2026-8757
|
2026-05-20 06:26 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5321
|
6.5 |
MEDIUM
Network
|
kilo
|
kilo_code
|
A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component Fi…
|
CWE-22
Path Traversal
|
CVE-2026-8765
|
2026-05-20 06:21 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5322
|
5.3 |
MEDIUM
Network
|
-
|
-
|
In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g. `"my_…
|
CWE-863
Incorrect Authorization
|
CVE-2026-42526
|
2026-05-20 06:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5323
|
8.7 |
HIGH
Local
|
-
|
-
|
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actio…
|
CWE-538
File and Directory Information Exposure
|
CVE-2026-27173
|
2026-05-20 06:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5324
|
- |
-
|
-
|
-
|
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain a…
|
CWE-862
Missing Authorization
|
CVE-2026-34154
|
2026-05-20 06:08 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5325
|
5.9 |
MEDIUM
Network
|
-
|
-
|
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attack…
|
CWE-863
Incorrect Authorization
|
CVE-2026-41470
|
2026-05-20 06:08 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5326
|
- |
-
|
-
|
-
|
Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 …
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-8370
|
2026-05-20 06:01 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5327
|
8.8 |
HIGH
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/acco…
|
CWE-269 CWE-434
Improper Privilege Management Unrestricted Upload of File with Dangerous Type
|
CVE-2026-42844
|
2026-05-20 06:00 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5328
|
7.5 |
HIGH
Network
|
-
|
-
|
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in …
|
CWE-23
Relative Path Traversal
|
CVE-2026-8073
|
2026-05-20 06:00 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5329
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not p…
|
CWE-862
Missing Authorization
|
CVE-2026-8096
|
2026-05-20 06:00 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5330
|
7.8 |
HIGH
Local
|
protobufjs_project
|
protobufjs-cli
|
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process…
|
CWE-78
OS Command
|
CVE-2026-42290
|
2026-05-20 05:56 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5331
|
5.3 |
MEDIUM
Network
|
protobufjs_project
|
protobufjs
|
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded …
|
CWE-176
Improper Handling of Unicode Encoding
|
CVE-2026-44288
|
2026-05-20 05:46 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5332
|
8.7 |
HIGH
Network
|
protobufjs_project
|
protobufjs-cli
|
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When ge…
|
CWE-94
Code Injection
|
CVE-2026-44295
|
2026-05-20 05:37 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5333
|
7.2 |
HIGH
Network
|
dkfz
|
nnu-net
|
nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable…
|
CWE-74
Injection
|
CVE-2026-44246
|
2026-05-20 05:10 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5334
|
6.1 |
MEDIUM
Network
|
beaugunderson
|
ip-address
|
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before…
|
CWE-79
Cross-site Scripting
|
CVE-2026-42338
|
2026-05-20 05:04 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5335
|
8.8 |
HIGH
Network
|
tabby
|
tabby
|
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supp…
|
CWE-78
OS Command
|
CVE-2026-45035
|
2026-05-20 04:41 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5336
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: …
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8567
|
2026-05-20 04:28 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5337
|
7.1 |
HIGH
Network
|
tabby
|
tabby
|
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without …
|
CWE-184 CWE-601
Incomplete Blacklist Open Redirect
|
CVE-2026-45037
|
2026-05-20 04:27 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5338
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity:…
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8573
|
2026-05-20 04:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5339
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM…
|
CWE-416
Use After Free
|
CVE-2026-8574
|
2026-05-20 04:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5340
|
9.4 |
CRITICAL
Network
|
dify
|
dify
|
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficie…
|
CWE-23
Relative Path Traversal
|
CVE-2026-41948
|
2026-05-20 04:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5341
|
9.1 |
CRITICAL
Network
|
dify
|
dify
|
Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant own…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41947
|
2026-05-20 04:24 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5342
|
7.2 |
HIGH
Network
|
dataease
|
dataease
|
A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-8724
|
2026-05-20 04:04 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5343
|
6.5 |
MEDIUM
Local
|
xen
|
xen
|
Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES
command within a transaction due to an assert() triggering.
In case xenstored was built with NDEBUG #defined nothing bad will
hap…
|
CWE-617
Reachable Assertion
|
CVE-2026-23557
|
2026-05-20 03:56 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5344
|
7.8 |
HIGH
Local
|
xen
|
xen
|
The adjustments made for XSA-379 as well as those subsequently becoming
XSA-387 still left a race window, when a HVM or PVH guest does a grant
table version change from v2 to v1 in parallel with mapp…
|
CWE-362
Race Condition
|
CVE-2026-23558
|
2026-05-20 03:55 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5345
|
7.5 |
HIGH
Network
|
langgenius
|
dify
|
Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document acr…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41949
|
2026-05-20 03:50 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5346
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8946
|
2026-05-20 03:50 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5347
|
7.3 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-416
Use After Free
|
CVE-2026-8947
|
2026-05-20 03:47 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5348
|
9.6 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140…
|
CWE-416
Use After Free
|
CVE-2026-8953
|
2026-05-20 03:45 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5349
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8954
|
2026-05-20 03:42 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5350
|
4.3 |
MEDIUM
Network
|
microsoft
|
365_apps office office_long_term_servicing_channel word
|
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
|
CWE-73
External Control of File Name or Path
|
CVE-2026-40421
|
2026-05-20 03:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|