|
6001
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized v…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48216
|
2026-05-22 03:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6002
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized valu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48215
|
2026-05-22 03:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6003
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized valu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48214
|
2026-05-22 03:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6004
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects HAPPY: from n/a through 1.0.10.
|
CWE-862
Missing Authorization
|
CVE-2026-39593
|
2026-05-22 03:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6005
|
7.8 |
HIGH
Local
|
-
|
-
|
MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-22554
|
2026-05-22 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6006
|
9.1 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8602
|
2026-05-22 02:19 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6007
|
9.8 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
|
CWE-78
OS Command
|
CVE-2026-8603
|
2026-05-22 02:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6008
|
8.8 |
HIGH
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
|
CWE-352
Origin Validation Error
|
CVE-2026-8604
|
2026-05-22 02:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6009
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48213
|
2026-05-22 02:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6010
|
9.8 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-8605
|
2026-05-22 02:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6011
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: M…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8564
|
2026-05-22 02:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6012
|
4.7 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafte…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8565
|
2026-05-22 02:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6013
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8569
|
2026-05-22 02:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6014
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security sev…
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-8576
|
2026-05-22 02:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6015
|
3.1 |
LOW
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chro…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8578
|
2026-05-22 02:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6016
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome E…
|
CWE-416
Use After Free
|
CVE-2026-8587
|
2026-05-22 02:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6017
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium se…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8563
|
2026-05-22 02:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6018
|
8.1 |
HIGH
Network
|
memcached
|
memcached
|
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-47783
|
2026-05-22 02:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6019
|
8.1 |
HIGH
Network
|
memcached
|
memcached
|
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-47784
|
2026-05-22 02:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6020
|
6.5 |
MEDIUM
Network
|
veritas
|
infoscale_operations_manager
|
SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.
|
CWE-89
SQL Injection
|
CVE-2026-44923
|
2026-05-22 01:57 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6021
|
5.4 |
MEDIUM
Network
|
veritas
|
infoscale_operations_manager
|
InfoScale VIOM 9.1.3 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2026-44924
|
2026-05-22 01:57 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6022
|
8.8 |
HIGH
Adjacent
|
veritas
|
infoscale_operations_manager
|
Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which t…
|
CWE-352
Origin Validation Error
|
CVE-2026-44925
|
2026-05-22 01:57 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6023
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML pag…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-9110
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6024
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-9111
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6025
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi…
|
CWE-416
Use After Free
|
CVE-2026-9112
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6026
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9113
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6027
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Hig…
|
CWE-416
Use After Free
|
CVE-2026-9114
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6028
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severi…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-9115
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6029
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: …
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-9116
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6030
|
6.5 |
MEDIUM
Network
|
plane
|
plane
|
Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without vali…
|
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-40102
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6031
|
6.1 |
MEDIUM
Network
|
obfuscate_project
|
obfuscate
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (XSS).
This issue affects Obfuscate: from 0.0.0 bef…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6871
|
2026-05-22 01:52 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6032
|
6.1 |
MEDIUM
Network
|
gaya
|
orejime
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (XSS).
This issue affects Orejime: from 0.0.0 before …
|
CWE-79
Cross-site Scripting
|
CVE-2026-6095
|
2026-05-22 01:46 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6033
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craf…
|
CWE-843
Type Confusion
|
CVE-2026-9117
|
2026-05-22 01:45 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6034
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-9118
|
2026-05-22 01:45 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6035
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-9119
|
2026-05-22 01:44 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6036
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-9120
|
2026-05-22 01:41 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6037
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9121
|
2026-05-22 01:35 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6038
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9122
|
2026-05-22 01:32 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6039
|
7.5 |
HIGH
Adjacent
|
google
|
chrome
|
Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traff…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-9123
|
2026-05-22 01:31 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6040
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a craf…
|
CWE-20
Improper Input Validation
|
CVE-2026-9124
|
2026-05-22 01:25 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6041
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-416
Use After Free
|
CVE-2026-9126
|
2026-05-22 01:23 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6042
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected.
In certain scenarios, an…
|
CWE-269
Improper Privilege Management
|
CVE-2026-45254
|
2026-05-22 01:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6043
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.
This issue affects WP Directory Ki…
|
CWE-89
SQL Injection
|
CVE-2026-39531
|
2026-05-22 01:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6044
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106fedb4a4f510972bdc allows a local attacker to cause a denial…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36189
|
2026-05-22 01:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6045
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authenticati…
|
CWE-284
Improper Access Control
|
CVE-2026-2734
|
2026-05-22 01:08 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6046
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2026-30691
|
2026-05-22 01:08 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6047
|
3.3 |
LOW
Local
|
-
|
-
|
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web p…
|
CWE-357
Insufficient UI Warning of Dangerous Operations
|
CVE-2026-47782
|
2026-05-22 01:08 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6048
|
- |
-
|
-
|
-
|
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Ma…
|
CWE-23
Relative Path Traversal
|
CVE-2026-23734
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6049
|
6.1 |
MEDIUM
Network
|
-
|
-
|
CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted …
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-26028
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6050
|
7.5 |
HIGH
Network
|
-
|
-
|
Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks.
These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying has…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-47373
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|