|
6901
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exh…
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-6340
|
2026-05-20 02:21 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6902
|
7.5 |
HIGH
Network
|
hsclabs
|
mailinspector
|
HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without …
|
CWE-22
Path Traversal
|
CVE-2026-29963
|
2026-05-20 02:21 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6903
|
6.1 |
MEDIUM
Network
|
hsclabs
|
mailinspector
|
HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaS…
|
CWE-79
Cross-site Scripting
|
CVE-2026-29964
|
2026-05-20 02:20 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6904
|
6.1 |
MEDIUM
Network
|
hsclabs
|
mailinspector
|
HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscate…
|
CWE-79
Cross-site Scripting
|
CVE-2026-29965
|
2026-05-20 02:19 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6905
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with…
|
CWE-863
Incorrect Authorization
|
CVE-2026-28732
|
2026-05-20 02:18 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6906
|
5.0 |
MEDIUM
Network
|
-
|
-
|
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backen…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-33234
|
2026-05-20 02:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6907
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input…
|
CWE-78
OS Command
|
CVE-2026-27130
|
2026-05-20 02:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6908
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8548
|
2026-05-20 02:02 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6909
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-8549
|
2026-05-20 01:58 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6910
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memo…
|
CWE-416
Use After Free
|
CVE-2026-8550
|
2026-05-20 01:51 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6911
|
7.5 |
HIGH
Network
|
dhtmlx
|
pdf_export_module
|
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could incl…
|
CWE-22
Path Traversal
|
CVE-2026-41552
|
2026-05-20 01:49 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6912
|
7.5 |
HIGH
Network
|
twisted
|
twisted
|
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exha…
|
CWE-400 CWE-407
Uncontrolled Resource Consumption Inefficient Algorithmic Complexity
|
CVE-2026-42304
|
2026-05-20 01:47 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6913
|
6.1 |
MEDIUM
Network
|
northern.tech
|
cfengine
|
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2026-24710
|
2026-05-20 01:45 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6914
|
5.3 |
MEDIUM
Network
|
northern.tech
|
cfengine
|
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
|
CWE-284
Improper Access Control
|
CVE-2026-24711
|
2026-05-20 01:44 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6915
|
7.3 |
HIGH
Network
|
northern.tech
|
cfengine
|
Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
|
CWE-77
Command Injection
|
CVE-2026-24712
|
2026-05-20 01:43 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6916
|
8.8 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the /api/v1/utils/code/execute endpoint executes arbitrary Python code via Jupyter …
|
CWE-863
Incorrect Authorization
|
CVE-2026-45672
|
2026-05-20 01:39 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6917
|
8.7 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, Excel file attachments are previewed in an unsafe way. A crafted XLSX file payload c…
|
CWE-79
Cross-site Scripting
|
CVE-2026-44549
|
2026-05-20 01:38 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6918
|
8.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the name of the file is derived from the original HTT…
|
CWE-22
Path Traversal
|
CVE-2026-44565
|
2026-05-20 01:38 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6919
|
7.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, there's an IDOR in the channels message management system that allows authenticated…
|
CWE-862
Missing Authorization
|
CVE-2026-44569
|
2026-05-20 01:38 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6920
|
7.3 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly validate that the user has an authorized user role of us…
|
CWE-602 CWE-863
Client-Side Enforcement of Server-Side Security Incorrect Authorization
|
CVE-2026-44567
|
2026-05-20 01:38 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6921
|
6.5 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24…
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-29207
|
2026-05-20 01:37 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6922
|
6.5 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to v…
|
CWE-22
Path Traversal
|
CVE-2026-29220
|
2026-05-20 01:37 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6923
|
6.5 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-31380
|
2026-05-20 01:37 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6924
|
5.3 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Authentication vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
|
CWE-287
Improper Authentication
|
CVE-2026-31387
|
2026-05-20 01:36 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6925
|
5.3 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixe…
|
CWE-284
Improper Access Control
|
CVE-2026-31388
|
2026-05-20 01:36 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6926
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrad…
|
CWE-79
Cross-site Scripting
|
CVE-2026-31906
|
2026-05-20 01:36 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6927
|
7.5 |
HIGH
Network
|
apache
|
ofbiz
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, whi…
|
CWE-200
Information Exposure
|
CVE-2026-31909
|
2026-05-20 01:36 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6928
|
7.5 |
HIGH
Network
|
apache
|
ofbiz
|
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-31910
|
2026-05-20 01:36 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6929
|
9.1 |
CRITICAL
Network
|
apache
|
ofbiz
|
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-31986
|
2026-05-20 01:36 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6930
|
6.5 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to vers…
|
CWE-94
Code Injection
|
CVE-2026-35086
|
2026-05-20 01:36 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6931
|
9.1 |
CRITICAL
Network
|
apache
|
ofbiz
|
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrad…
|
CWE-90
LDAP Injection
|
CVE-2026-41919
|
2026-05-20 01:35 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6932
|
6.5 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Authorization vulnerability in Apache OFBiz Webtools.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
|
CWE-285
Improper Authorization
|
CVE-2026-45187
|
2026-05-20 01:35 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6933
|
9.1 |
CRITICAL
Network
|
freedesktop
|
gst-plugins-good
|
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before per…
|
CWE-369
Divide By Zero
|
CVE-2026-46470
|
2026-05-20 01:34 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6934
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via…
|
CWE-862
Missing Authorization
|
CVE-2026-8547
|
2026-05-20 01:33 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6935
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information fr…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8546
|
2026-05-20 01:33 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6936
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive infor…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8543
|
2026-05-20 01:33 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6937
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM…
|
CWE-416
Use After Free
|
CVE-2026-8542
|
2026-05-20 01:32 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6938
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a …
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8585
|
2026-05-20 01:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6939
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8584
|
2026-05-20 01:29 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6940
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
|
CWE-416
Use After Free
|
CVE-2026-8530
|
2026-05-20 01:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6941
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8531
|
2026-05-20 01:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6942
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8534
|
2026-05-20 01:26 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6943
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informati…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8535
|
2026-05-20 01:26 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6944
|
3.1 |
LOW
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass site Isolation v…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-8536
|
2026-05-20 01:26 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6945
|
9.8 |
CRITICAL
Network
|
wgdashboard
|
wgdashboard
|
WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file sys…
|
CWE-20
Improper Input Validation
|
CVE-2026-44343
|
2026-05-20 01:21 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6946
|
7.6 |
HIGH
Network
|
pocketbase
|
pocketbase
|
Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and link an unverified Po…
|
CWE-287
Improper Authentication
|
CVE-2026-44166
|
2026-05-20 01:20 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6947
|
5.4 |
MEDIUM
Network
|
google
|
chrome
|
Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security s…
|
CWE-94
Code Injection
|
CVE-2026-8539
|
2026-05-20 01:18 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6948
|
8.8 |
HIGH
Network
|
axis
|
axis_os
|
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-1185
|
2026-05-20 01:07 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6949
|
7.3 |
HIGH
Local
|
axis
|
axis_os
|
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axi…
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2026-0804
|
2026-05-20 01:06 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6950
|
7.3 |
HIGH
Local
|
axis
|
axis_os
|
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis d…
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2026-0802
|
2026-05-20 01:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|