|
6151
|
7.8 |
HIGH
Local
|
-
|
-
|
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations.
Please not…
|
CWE-346
Origin Validation Error
|
CVE-2025-71217
|
2026-05-22 00:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6152
|
7.8 |
HIGH
Local
|
-
|
-
|
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations.
Please note: an att…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-71216
|
2026-05-22 00:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6153
|
7.0 |
HIGH
Local
|
-
|
-
|
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations.
…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-71215
|
2026-05-22 00:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6154
|
7.8 |
HIGH
Local
|
-
|
-
|
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations.
Please note: an attack…
|
CWE-346
Origin Validation Error
|
CVE-2025-71214
|
2026-05-22 00:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6155
|
7.8 |
HIGH
Local
|
-
|
-
|
MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability
|
CWE-823
Use of Out-of-range Pointer Offset
|
CVE-2026-28764
|
2026-05-22 00:05 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6156
|
7.5 |
HIGH
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-20239
|
2026-05-22 00:00 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6157
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, …
|
CWE-20
Improper Input Validation
|
CVE-2026-20240
|
2026-05-22 00:00 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6158
|
7.1 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ptrace: slightly saner 'get_dumpable()' logic
The 'dumpability' of a task is fundamentally about the memory image of
the task - t…
|
CWE-269
Improper Privilege Management
|
CVE-2026-46333
|
2026-05-21 23:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6159
|
8.8 |
HIGH
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-32740
|
2026-05-21 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6160
|
9.1 |
CRITICAL
Network
|
eclipse
|
glassfish
|
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of …
|
CWE-94 CWE-917
Code Injection Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-2586
|
2026-05-21 22:18 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6161
|
9.6 |
CRITICAL
Network
|
eclipse
|
glassfish
|
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and eval…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-2587
|
2026-05-21 22:18 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6162
|
7.5 |
HIGH
Network
|
nvidia
|
tensorrt_llm
|
NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead …
|
CWE-690
Unchecked Return Value to NULL Pointer Dereference
|
CVE-2026-24160
|
2026-05-21 22:09 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6163
|
9.8 |
CRITICAL
Network
|
nvidia
|
tensorrt_llm
|
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code executio…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-33255
|
2026-05-21 09:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6164
|
9.8 |
CRITICAL
Network
|
nvidia
|
tensorrt_llm
|
NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and i…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24142
|
2026-05-21 09:04 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6165
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-8399
|
2026-05-21 08:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6166
|
3.1 |
LOW
Network
|
emqx
|
emqx
|
A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH Packet Handler. Such manip…
|
CWE-362
Race Condition
|
CVE-2026-8741
|
2026-05-21 08:02 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6167
|
8.1 |
HIGH
Network
|
microsoft
|
malware_protection_engine
|
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45584
|
2026-05-21 03:56 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6168
|
7.8 |
HIGH
Local
|
microsoft
|
windows_admin_center
|
Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
|
CWE-59
Link Following
|
CVE-2026-42834
|
2026-05-21 03:29 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6169
|
5.8 |
MEDIUM
Network
|
-
|
-
|
The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attack…
|
-
|
CVE-2026-7385
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6170
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
|
CWE-59
Link Following
|
CVE-2026-41091
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6171
|
4.8 |
MEDIUM
Network
|
-
|
-
|
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In a…
|
CWE-80 CWE-116
Basic XSS Improper Encoding or Escaping of Output
|
CVE-2026-34246
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6172
|
7.1 |
HIGH
Network
|
-
|
-
|
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overla…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-32882
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6173
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8961
|
2026-05-21 02:58 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6174
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
|
CWE-200
Information Exposure
|
CVE-2026-8967
|
2026-05-21 02:57 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6175
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8962
|
2026-05-21 02:56 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6176
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
|
CWE-200
Information Exposure
|
CVE-2026-8965
|
2026-05-21 02:51 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6177
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
|
CWE-200
Information Exposure
|
CVE-2026-8966
|
2026-05-21 02:51 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6178
|
7.5 |
HIGH
Network
|
progress
|
moveit_automation
|
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.
This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-8485
|
2026-05-21 02:50 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6179
|
4.6 |
MEDIUM
Network
|
nozominetworks
|
cmc guardian
|
An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a mal…
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2025-40900
|
2026-05-21 02:35 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6180
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-269
Improper Privilege Management
|
CVE-2026-8970
|
2026-05-21 02:34 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6181
|
6.5 |
MEDIUM
Network
|
kilo
|
kilo_code_cli
|
A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executi…
|
CWE-200 CWE-284 NVD-CWE-noinfo
Information Exposure Improper Access Control
|
CVE-2026-8766
|
2026-05-21 02:34 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6182
|
4.0 |
MEDIUM
Physics
|
-
|
-
|
Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of m…
|
CWE-682
Incorrect Calculation
|
CVE-2023-7346
|
2026-05-21 02:33 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6183
|
7.2 |
HIGH
Network
|
-
|
-
|
The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-7613
|
2026-05-21 02:33 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6184
|
6.4 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId,
idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-9087
|
2026-05-21 02:32 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6185
|
5.9 |
MEDIUM
Network
|
-
|
-
|
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads t…
|
CWE-1285
Improper Validation of Specified Index, Position, or Offset in Input
|
CVE-2026-9100
|
2026-05-21 02:32 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6186
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execu…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-9101
|
2026-05-21 02:32 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6187
|
7.5 |
HIGH
Network
|
-
|
-
|
Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-39047
|
2026-05-21 02:31 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6188
|
- |
-
|
-
|
-
|
MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecu…
|
CWE-287
Improper Authentication
|
CVE-2026-9084
|
2026-05-21 02:31 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6189
|
- |
-
|
-
|
-
|
InfoScale CmdServer before 7.4.2 mishandles access control.
|
-
|
CVE-2026-44926
|
2026-05-21 02:31 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6190
|
9.8 |
CRITICAL
Network
|
nvidia
|
triton_inference_server
|
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, deni…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-24206
|
2026-05-21 02:31 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6191
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS.
This i…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5783
|
2026-05-21 02:30 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6192
|
9.8 |
CRITICAL
Network
|
nvidia
|
triton_inference_server
|
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of …
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-24207
|
2026-05-21 02:30 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6193
|
7.5 |
HIGH
Network
|
-
|
-
|
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit thi…
|
CWE-548
Exposure of Information Through Directory Listing
|
CVE-2025-32750
|
2026-05-21 02:30 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6194
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the brow…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4293
|
2026-05-21 02:30 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6195
|
9.1 |
CRITICAL
Network
|
-
|
-
|
An undocumented configuration export port is accessible on some models
of ZKTeco CCTV cameras. This port does not require authentication and
exposes critical information about the camera such as op…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-8598
|
2026-05-21 02:30 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6196
|
6.8 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow a…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2026-20171
|
2026-05-21 02:30 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6197
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the roo…
|
CWE-74
Injection
|
CVE-2026-20199
|
2026-05-21 02:30 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6198
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the Browse…
|
CWE-78
OS Command
|
CVE-2026-20206
|
2026-05-21 02:30 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6199
|
10.0 |
CRITICAL
Network
|
-
|
-
|
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the S…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-20223
|
2026-05-21 02:30 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6200
|
7.5 |
HIGH
Network
|
nvidia
|
triton_inference_server
|
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.
|
CWE-22
Path Traversal
|
CVE-2026-24208
|
2026-05-21 02:29 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|