|
6451
|
8.1 |
HIGH
Network
|
memcached
|
memcached
|
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-47784
|
2026-05-22 02:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6452
|
6.5 |
MEDIUM
Network
|
veritas
|
infoscale_operations_manager
|
SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.
|
CWE-89
SQL Injection
|
CVE-2026-44923
|
2026-05-22 01:57 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6453
|
5.4 |
MEDIUM
Network
|
veritas
|
infoscale_operations_manager
|
InfoScale VIOM 9.1.3 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2026-44924
|
2026-05-22 01:57 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6454
|
8.8 |
HIGH
Adjacent
|
veritas
|
infoscale_operations_manager
|
Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which t…
|
CWE-352
Origin Validation Error
|
CVE-2026-44925
|
2026-05-22 01:57 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6455
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML pag…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-9110
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6456
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-9111
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6457
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi…
|
CWE-416
Use After Free
|
CVE-2026-9112
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6458
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9113
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6459
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Hig…
|
CWE-416
Use After Free
|
CVE-2026-9114
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6460
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severi…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-9115
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6461
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: …
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-9116
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6462
|
6.5 |
MEDIUM
Network
|
plane
|
plane
|
Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without vali…
|
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-40102
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6463
|
6.1 |
MEDIUM
Network
|
obfuscate_project
|
obfuscate
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (XSS).
This issue affects Obfuscate: from 0.0.0 bef…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6871
|
2026-05-22 01:52 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6464
|
6.1 |
MEDIUM
Network
|
gaya
|
orejime
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (XSS).
This issue affects Orejime: from 0.0.0 before …
|
CWE-79
Cross-site Scripting
|
CVE-2026-6095
|
2026-05-22 01:46 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6465
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craf…
|
CWE-843
Type Confusion
|
CVE-2026-9117
|
2026-05-22 01:45 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6466
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-9118
|
2026-05-22 01:45 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6467
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-9119
|
2026-05-22 01:44 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6468
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-9120
|
2026-05-22 01:41 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6469
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9121
|
2026-05-22 01:35 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6470
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9122
|
2026-05-22 01:32 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6471
|
7.5 |
HIGH
Adjacent
|
google
|
chrome
|
Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traff…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-9123
|
2026-05-22 01:31 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6472
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a craf…
|
CWE-20
Improper Input Validation
|
CVE-2026-9124
|
2026-05-22 01:25 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6473
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-416
Use After Free
|
CVE-2026-9126
|
2026-05-22 01:23 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6474
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected.
In certain scenarios, an…
|
CWE-269
Improper Privilege Management
|
CVE-2026-45254
|
2026-05-22 01:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6475
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.
This issue affects WP Directory Ki…
|
CWE-89
SQL Injection
|
CVE-2026-39531
|
2026-05-22 01:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6476
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106fedb4a4f510972bdc allows a local attacker to cause a denial…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36189
|
2026-05-22 01:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6477
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authenticati…
|
CWE-284
Improper Access Control
|
CVE-2026-2734
|
2026-05-22 01:08 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6478
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2026-30691
|
2026-05-22 01:08 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6479
|
3.3 |
LOW
Local
|
-
|
-
|
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web p…
|
CWE-357
Insufficient UI Warning of Dangerous Operations
|
CVE-2026-47782
|
2026-05-22 01:08 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6480
|
- |
-
|
-
|
-
|
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Ma…
|
CWE-23
Relative Path Traversal
|
CVE-2026-23734
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6481
|
6.1 |
MEDIUM
Network
|
-
|
-
|
CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted …
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-26028
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6482
|
7.5 |
HIGH
Network
|
-
|
-
|
Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks.
These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying has…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-47373
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6483
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a textarea custom field's contents in the Update Issue p…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39960
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6484
|
7.5 |
HIGH
Network
|
-
|
-
|
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademli…
|
CWE-252
Unchecked Return Value
|
CVE-2026-40092
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6485
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts.
These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2026-47372
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6486
|
4.3 |
MEDIUM
Network
|
-
|
-
|
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and s…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-40094
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6487
|
- |
-
|
-
|
-
|
The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients,…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-9137
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6488
|
- |
-
|
-
|
-
|
A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-9136
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6489
|
- |
-
|
-
|
-
|
The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerabil…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-0393
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6490
|
- |
-
|
-
|
-
|
Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary Jav…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6841
|
2026-05-22 01:04 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6491
|
7.8 |
HIGH
Local
|
-
|
-
|
NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of serv…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24216
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6492
|
8.8 |
HIGH
Network
|
-
|
-
|
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, …
|
CWE-29
Path Traversal: '\..\filename'
|
CVE-2026-24217
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6493
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could …
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-9150
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6494
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. T…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-9149
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6495
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook run which allows an authenticated team member to create runs in…
|
CWE-863
Incorrect Authorization
|
CVE-2026-4055
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6496
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Ma…
|
CWE-352
Origin Validation Error
|
CVE-2026-22880
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6497
|
8.0 |
HIGH
Network
|
-
|
-
|
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an…
|
CWE-22
Path Traversal
|
CVE-2026-4858
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6498
|
8.4 |
HIGH
Network
|
-
|
-
|
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent mac…
|
CWE-77
Command Injection
|
CVE-2026-2740
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6499
|
7.1 |
HIGH
Network
|
-
|
-
|
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass.
Thi…
|
CWE-359 CWE-522
Exposure of Private Personal Information to an Unauthorized Actor Insufficiently Protected Credentials
|
CVE-2025-13477
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6500
|
7.5 |
HIGH
Network
|
-
|
-
|
Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers.
This issue affects QR Menu: throug…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-13479
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|