|
6201
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS.
This issue affects Geo Mashup: from n/a through 1.13.18.
|
CWE-79
Cross-site Scripting
|
CVE-2026-27427
|
2026-05-26 18:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6202
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects RepairBuddy: from n/a through 4.1121.
|
CWE-862
Missing Authorization
|
CVE-2026-24638
|
2026-05-26 18:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6203
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Paid Videochat Turnkey…
|
CWE-862
Missing Authorization
|
CVE-2026-24590
|
2026-05-26 18:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6204
|
7.5 |
HIGH
Network
|
-
|
-
|
The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw t…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-8047
|
2026-05-26 17:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6205
|
8.1 |
HIGH
Network
|
-
|
-
|
The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including tho…
|
CWE-863
Incorrect Authorization
|
CVE-2026-8046
|
2026-05-26 17:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6206
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Mayosis Core: from n/a through 5.4.7.
|
CWE-862
Missing Authorization
|
CVE-2026-39655
|
2026-05-26 17:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6207
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint…
|
CWE-549
Missing Password Field Masking
|
CVE-2026-3314
|
2026-05-26 16:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6208
|
3.3 |
LOW
Local
|
-
|
-
|
A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulati…
|
CWE-404 CWE-476
Improper Resource Shutdown or Release NULL Pointer Dereference
|
CVE-2026-9529
|
2026-05-26 14:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6209
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9528
|
2026-05-26 14:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6210
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9527
|
2026-05-26 14:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6211
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id results in s…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9526
|
2026-05-26 14:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6212
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql in…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9525
|
2026-05-26 13:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6213
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportPa…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9524
|
2026-05-26 13:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6214
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of the file /Subs…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9523
|
2026-05-26 13:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6215
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to …
|
CWE-20 CWE-1287
Improper Input Validation Improper Validation of Specified Type of Input
|
CVE-2026-9521
|
2026-05-26 11:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6216
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the comp…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9520
|
2026-05-26 11:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6217
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of the component Sign-in Auto…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9519
|
2026-05-26 11:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6218
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. T…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9518
|
2026-05-26 11:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6219
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(A…
|
CWE-862
Missing Authorization
|
CVE-2026-4795
|
2026-05-26 11:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6220
|
- |
-
|
-
|
-
|
The GDPR cookies module for Backdrop CMS (before
1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info conte…
|
CWE-80
Basic XSS
|
CVE-2025-71310
|
2026-05-26 11:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6221
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student M…
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-9517
|
2026-05-26 09:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6222
|
5.4 |
MEDIUM
Network
|
webmin
|
webmin
|
Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attack…
|
CWE-79
Cross-site Scripting
|
CVE-2026-22678
|
2026-05-26 09:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6223
|
- |
-
|
-
|
-
|
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt d…
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2026-48700
|
2026-05-25 05:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6224
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net/rds: reset op_nents when zerocopy page pin fails
When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(),
the pinne…
|
-
|
CVE-2026-43494
|
2026-05-23 21:17 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6225
|
8.1 |
HIGH
Network
|
-
|
-
|
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which …
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9277
|
2026-05-23 13:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6226
|
- |
-
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2026-40598
|
2026-05-23 13:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6227
|
6.5 |
MEDIUM
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook) does not verify the x-hub…
|
CWE-287 CWE-345
Improper Authentication Insufficient Verification of Data Authenticity
|
CVE-2026-39969
|
2026-05-23 13:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6228
|
5.4 |
MEDIUM
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme.…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39964
|
2026-05-23 13:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6229
|
8.1 |
HIGH
Network
|
-
|
-
|
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can c…
|
CWE-610 CWE-639
Externally Controlled Reference to a Resource in Another Sphere Authorization Bypass Through User-Controlled Key
|
CVE-2026-45760
|
2026-05-23 12:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6230
|
8.1 |
HIGH
Network
|
-
|
-
|
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-9256
|
2026-05-23 10:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6231
|
6.8 |
MEDIUM
Physics
|
microsoft
|
windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2025
|
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coor…
|
CWE-77
Command Injection
|
CVE-2026-45585
|
2026-05-23 08:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6232
|
4.3 |
MEDIUM
Network
|
apache
|
cxf
|
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommende…
|
CWE-90
LDAP Injection
|
CVE-2026-44930
|
2026-05-23 07:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6233
|
5.3 |
MEDIUM
Network
|
apache
|
cxf
|
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this is…
|
CWE-611
XXE
|
CVE-2026-44618
|
2026-05-23 07:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6234
|
- |
-
|
-
|
-
|
TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload form. The application fails to sanitize or restri…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39970
|
2026-05-23 06:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6235
|
9.8 |
CRITICAL
Network
|
kovidgoyal
|
kitty
|
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned …
|
CWE-125 CWE-190 CWE-787
Out-of-bounds Read Integer Overflow or Wraparound Out-of-bounds Write
|
CVE-2026-33642
|
2026-05-23 06:05 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6236
|
8.8 |
HIGH
Network
|
kovidgoyal
|
kitty
|
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash ki…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-33633
|
2026-05-23 06:04 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6237
|
9.6 |
CRITICAL
Network
|
lfprojects
|
mlflow
|
In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests fr…
|
CWE-346
Origin Validation Error
|
CVE-2026-2611
|
2026-05-23 06:00 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6238
|
7.5 |
HIGH
Network
|
nvidia
|
tensorrt
|
NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.
|
CWE-787
Out-of-bounds Write
|
CVE-2026-24188
|
2026-05-23 05:52 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6239
|
8.2 |
HIGH
Network
|
dell
|
powerflex_appliance_intelligent_catalog powerflex_manager powerflex_rack
|
Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application …
|
CWE-601
Open Redirect
|
CVE-2025-26483
|
2026-05-23 05:48 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6240
|
6.5 |
MEDIUM
Adjacent
|
dell
|
powerflex_appliance_intelligent_catalog powerflex_manager powerflex_rack
|
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulner…
|
CWE-295
Improper Certificate Validation
|
CVE-2025-32745
|
2026-05-23 05:48 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6241
|
5.5 |
MEDIUM
Local
|
dell
|
powerflex_appliance_intelligent_catalog powerflex_manager powerflex_rack
|
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnera…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2025-32746
|
2026-05-23 05:45 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6242
|
7.8 |
HIGH
Local
|
dell
|
powerflex_appliance_intelligent_catalog powerflex_manager powerflex_rack
|
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leadi…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2025-32747
|
2026-05-23 05:45 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6243
|
7.5 |
HIGH
Network
|
dell
|
powerflex_appliance_intelligent_catalog powerflex_manager powerflex_rack
|
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit thi…
|
CWE-276
Incorrect Default Permissions
|
CVE-2025-32749
|
2026-05-23 05:44 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6244
|
8.2 |
HIGH
Local
|
-
|
-
|
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoT…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-5817
|
2026-05-23 05:44 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6245
|
8.2 |
HIGH
Local
|
-
|
-
|
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configur…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-5843
|
2026-05-23 05:44 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6246
|
5.5 |
MEDIUM
Local
|
dell
|
powerflex_appliance_intelligent_catalog powerflex_manager powerflex_rack
|
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabi…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2025-32751
|
2026-05-23 05:40 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6247
|
5.5 |
MEDIUM
Local
|
dell
|
powerflex_appliance_intelligent_catalog powerflex_manager powerflex_rack
|
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially explo…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2025-46371
|
2026-05-23 05:40 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6248
|
7.1 |
HIGH
Network
|
-
|
-
|
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve a…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9291
|
2026-05-23 05:31 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6249
|
- |
-
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTML by updating their account's font family. Upon explo…
|
CWE-79
Cross-site Scripting
|
CVE-2026-40596
|
2026-05-23 05:31 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6250
|
- |
-
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Pol…
|
CWE-79 CWE-358
Cross-site Scripting Improperly Implemented Security Check for Standard
|
CVE-2026-40597
|
2026-05-23 05:31 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|