|
7101
|
6.3 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in …
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-8743
|
2026-05-19 10:35 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7102
|
5.5 |
MEDIUM
Local
|
steipete
|
summarize
|
Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-45246
|
2026-05-19 10:34 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7103
|
5.4 |
MEDIUM
Network
|
steipete
|
summarize
|
Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation featu…
|
CWE-862
Missing Authorization
|
CVE-2026-45244
|
2026-05-19 10:34 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7104
|
7.1 |
HIGH
Network
|
steipete
|
summarize
|
Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolu…
|
CWE-862
Missing Authorization
|
CVE-2026-45242
|
2026-05-19 10:34 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7105
|
6.1 |
MEDIUM
Network
|
steipete
|
summarize
|
Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation a…
|
CWE-862
Missing Authorization
|
CVE-2026-45243
|
2026-05-19 10:34 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7106
|
7.4 |
HIGH
Network
|
steipete
|
summarize
|
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extensio…
|
CWE-918 CWE-940
Server-Side Request Forgery (SSRF) Improper Verification of Source of a Communication Channel
|
CVE-2026-45245
|
2026-05-19 10:34 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7107
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A flaw has been found in Open5GS up to 2.7.6. This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/sbi/context.c of the component NRF. Executing a manipulation of the argument nfI…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8730
|
2026-05-19 10:32 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7108
|
3.1 |
LOW
Network
|
google
|
chrome
|
Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Ch…
|
CWE-416
Use After Free
|
CVE-2026-8553
|
2026-05-19 10:31 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7109
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (C…
|
CWE-416
Use After Free
|
CVE-2026-8557
|
2026-05-19 10:31 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7110
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8558
|
2026-05-19 10:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7111
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: H…
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-8537
|
2026-05-19 10:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7112
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8532
|
2026-05-19 10:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7113
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
|
CWE-416
Use After Free
|
CVE-2026-8533
|
2026-05-19 10:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7114
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform a denial of service via a craf…
|
CWE-20
Improper Input Validation
|
CVE-2026-8538
|
2026-05-19 10:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7115
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-843
Type Confusion
|
CVE-2026-8540
|
2026-05-19 10:29 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7116
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /api/v1/memories/ef is accessible without authentication and executes request.ap…
|
CWE-862
Missing Authorization
|
CVE-2026-45667
|
2026-05-19 10:28 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7117
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowin…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45666
|
2026-05-19 10:28 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7118
|
8.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due…
|
CWE-79
Cross-site Scripting
|
CVE-2026-45665
|
2026-05-19 10:28 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7119
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based …
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-8733
|
2026-05-19 06:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7120
|
- |
-
|
-
|
-
|
* Countermeasures for DPA within SYMCRYPTO
engine on SixG301xxx devices are not sufficiently random and will
eventually repeat.
* KSU keys using SYMCRYPTO will be
impacted by this vulnerability.
|
CWE-331
Insufficient Entropy
|
CVE-2025-14972
|
2026-05-19 05:27 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7121
|
8.2 |
HIGH
Network
|
-
|
-
|
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control fu…
|
CWE-124
Buffer Underflow
|
CVE-2026-34253
|
2026-05-19 05:23 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7122
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-38728
|
2026-05-19 05:23 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7123
|
4.6 |
MEDIUM
Network
|
-
|
-
|
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
|
CWE-863
Incorrect Authorization
|
CVE-2026-21789
|
2026-05-19 05:23 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7124
|
8.2 |
HIGH
Local
|
-
|
-
|
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
|
CWE-346
Origin Validation Error
|
CVE-2026-46728
|
2026-05-19 05:23 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7125
|
4.6 |
MEDIUM
Local
|
-
|
-
|
Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded…
|
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
|
CVE-2026-47090
|
2026-05-19 05:19 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7126
|
3.3 |
LOW
Local
|
-
|
-
|
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin…
|
CWE-22
Path Traversal
|
CVE-2026-47091
|
2026-05-19 05:19 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7127
|
7.8 |
HIGH
Local
|
-
|
-
|
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment vari…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-47092
|
2026-05-19 05:19 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7128
|
9.8 |
CRITICAL
Network
|
-
|
-
|
iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retr…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-37228
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7129
|
7.8 |
HIGH
Local
|
-
|
-
|
Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-37231
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7130
|
9.8 |
CRITICAL
Network
|
-
|
-
|
libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_…
|
CWE-415
Double Free
|
CVE-2020-37239
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7131
|
9.8 |
CRITICAL
Network
|
-
|
-
|
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. …
|
CWE-94
Code Injection
|
CVE-2021-47952
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7132
|
7.8 |
HIGH
Local
|
-
|
-
|
OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-37229
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7133
|
7.8 |
HIGH
Local
|
-
|
-
|
Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-37230
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7134
|
7.5 |
HIGH
Network
|
-
|
-
|
Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoi…
|
CWE-22
Path Traversal
|
CVE-2021-47942
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7135
|
9.8 |
CRITICAL
Network
|
-
|
-
|
GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file uploa…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-25332
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7136
|
8.2 |
HIGH
Network
|
-
|
-
|
Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the …
|
CWE-89
SQL Injection
|
CVE-2018-25333
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7137
|
9.1 |
CRITICAL
Network
|
-
|
-
|
OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Core evaluates databas…
|
CWE-94
Code Injection
|
CVE-2026-41258
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7138
|
- |
-
|
-
|
-
|
LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL back…
|
CWE-327 CWE-347
Use of a Broken or Risky Cryptographic Algorithm Improper Verification of Cryptographic Signature
|
CVE-2026-44699
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7139
|
7.5 |
HIGH
Network
|
-
|
-
|
The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends() contains two fast-path verification bugs for standard P2PKH and native P2WPKH…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-44714
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7140
|
9.8 |
CRITICAL
Network
|
-
|
-
|
MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitiz…
|
CWE-94
Code Injection
|
CVE-2026-44717
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7141
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle…
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-46383
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7142
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hig…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8524
|
2026-05-19 04:43 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7143
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8526
|
2026-05-19 04:43 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7144
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severi…
|
CWE-20
Improper Input Validation
|
CVE-2026-8527
|
2026-05-19 04:42 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7145
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a …
|
CWE-20
Improper Input Validation
|
CVE-2026-8528
|
2026-05-19 04:42 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7146
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-37234
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7147
|
6.4 |
MEDIUM
Network
|
-
|
-
|
NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news additio…
|
CWE-79
Cross-site Scripting
|
CVE-2020-37236
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7148
|
8.2 |
HIGH
Network
|
-
|
-
|
EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the firstname parameter. Attackers…
|
CWE-89
SQL Injection
|
CVE-2021-47956
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7149
|
9.8 |
CRITICAL
Network
|
-
|
-
|
ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can …
|
CWE-94
Code Injection
|
CVE-2018-25320
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7150
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attac…
|
CWE-79
Cross-site Scripting
|
CVE-2018-25331
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|