|
7151
|
6.1 |
MEDIUM
Network
|
-
|
-
|
DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side san…
|
CWE-79
Cross-site Scripting
|
CVE-2026-45231
|
2026-05-19 04:42 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7152
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Hig…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8529
|
2026-05-19 04:41 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7153
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's …
|
CWE-295 CWE-347
Improper Certificate Validation Improper Verification of Cryptographic Signature
|
CVE-2026-44309
|
2026-05-19 04:36 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7154
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereference…
|
CWE-129 CWE-390
Improper Validation of Array Index Detection of Error Condition Without Action
|
CVE-2026-44310
|
2026-05-19 04:36 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7155
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr…
|
CWE-601
Open Redirect
|
CVE-2026-42207
|
2026-05-19 04:35 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7156
|
- |
-
|
-
|
-
|
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr…
|
CWE-87
Improper Neutralization of Alternate XSS Syntax
|
CVE-2026-42458
|
2026-05-19 04:35 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7157
|
- |
-
|
-
|
-
|
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr…
|
CWE-330 CWE-331 CWE-338
Use of Insufficiently Random Values Insufficient Entropy Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2026-42155
|
2026-05-19 04:35 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7158
|
7.1 |
HIGH
Local
|
-
|
-
|
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by copying plugin components referenced in plugin.jso…
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-44641
|
2026-05-19 04:33 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7159
|
7.4 |
HIGH
Network
|
-
|
-
|
Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rgl…
|
CWE-59 CWE-200
Link Following Information Exposure
|
CVE-2026-45539
|
2026-05-19 04:33 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7160
|
- |
-
|
-
|
-
|
An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive…
|
CWE-862
Missing Authorization
|
CVE-2026-2031
|
2026-05-19 04:32 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7161
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation cau…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-8725
|
2026-05-19 04:31 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7162
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipu…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-8747
|
2026-05-19 04:31 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7163
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is the function _get_all_models of the file hiyoriUI.py of the component Model Handl…
|
CWE-22
Path Traversal
|
CVE-2026-8755
|
2026-05-19 04:31 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7164
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_config of the file webui_preprocess.py of the comp…
|
CWE-22
Path Traversal
|
CVE-2026-8756
|
2026-05-19 04:31 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7165
|
7.2 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffe…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-8764
|
2026-05-19 04:31 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7166
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-8836
|
2026-05-19 04:26 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7167
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFuncti…
|
CWE-20 CWE-917
Improper Input Validation Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-8759
|
2026-05-19 04:22 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7168
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentia…
|
CWE-20
Improper Input Validation
|
CVE-2026-8516
|
2026-05-19 04:17 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7169
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-8518
|
2026-05-19 04:17 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7170
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-362
Race Condition
|
CVE-2026-8520
|
2026-05-19 04:17 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7171
|
7.5 |
HIGH
Adjacent
|
google
|
chrome
|
Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-8521
|
2026-05-19 04:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7172
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
|
CWE-416
Use After Free
|
CVE-2026-8523
|
2026-05-19 04:14 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7173
|
10.0 |
CRITICAL
Network
|
dhtmlx
|
pdf_export_module
|
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicio…
|
CWE-78
OS Command
|
CVE-2026-41553
|
2026-05-19 03:40 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7174
|
8.7 |
HIGH
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermo…
|
CWE-200
Information Exposure
|
CVE-2026-6346
|
2026-05-19 03:39 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7175
|
7.6 |
HIGH
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a su…
|
CWE-200
Information Exposure
|
CVE-2026-6347
|
2026-05-19 03:39 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7176
|
9.8 |
CRITICAL
Network
|
radare
|
radare2
|
radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed b…
|
CWE-416
Use After Free
|
CVE-2026-8695
|
2026-05-19 03:38 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7177
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, a…
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2026-4053
|
2026-05-19 03:37 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7178
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG fi…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-4054
|
2026-05-19 03:36 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7179
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF. The manipulation of the argument client_pool …
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8731
|
2026-05-19 03:35 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7180
|
9.1 |
CRITICAL
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is no…
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2026-44551
|
2026-05-19 03:35 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7181
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of the argument service-names/s…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8729
|
2026-05-19 03:35 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7182
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. S…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8728
|
2026-05-19 03:35 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7183
|
4.3 |
MEDIUM
Network
|
tp-link
|
tl-wr720n_firmware
|
TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attacker…
|
CWE-352
Origin Validation Error
|
CVE-2018-25321
|
2026-05-19 03:34 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7184
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing …
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8744
|
2026-05-19 03:34 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7185
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Criti…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8509
|
2026-05-19 03:34 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7186
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the component AUSF. The manipulation le…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8745
|
2026-05-19 03:34 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7187
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-8511
|
2026-05-19 03:34 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7188
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a cr…
|
CWE-416
Use After Free
|
CVE-2026-8512
|
2026-05-19 03:33 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7189
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
|
CWE-416
Use After Free
|
CVE-2026-8514
|
2026-05-19 03:33 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7190
|
8.7 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When t…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2026-44552
|
2026-05-19 03:32 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7191
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted H…
|
CWE-416
Use After Free
|
CVE-2026-8515
|
2026-05-19 03:32 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7192
|
5.3 |
MEDIUM
Network
|
pyload
|
pyload
|
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<p…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-44226
|
2026-05-19 03:25 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7193
|
6.5 |
MEDIUM
Network
|
guimard
|
apache\
|
Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids.
Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator re…
|
CWE-338 CWE-340
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Generation of Predictable Numbers or Identifiers
|
CVE-2026-8503
|
2026-05-19 03:23 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7194
|
5.4 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8561
|
2026-05-19 03:22 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7195
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Mediu…
|
CWE-1300
Improper Protection of Physical Side Channels
|
CVE-2026-8562
|
2026-05-19 03:21 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7196
|
9.1 |
CRITICAL
Network
|
-
|
-
|
DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary fi…
|
CWE-22
Path Traversal
|
CVE-2026-45230
|
2026-05-19 03:17 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7197
|
8.8 |
HIGH
Network
|
-
|
-
|
Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrato…
|
CWE-269
Improper Privilege Management
|
CVE-2026-41085
|
2026-05-19 03:17 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7198
|
6.2 |
MEDIUM
Local
|
-
|
-
|
OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A c…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-38719
|
2026-05-19 03:17 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7199
|
5.5 |
MEDIUM
Local
|
-
|
-
|
NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed i…
|
CWE-190 CWE-476
Integer Overflow or Wraparound NULL Pointer Dereference
|
CVE-2026-32849
|
2026-05-19 03:17 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7200
|
4.7 |
MEDIUM
Local
|
-
|
-
|
NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently…
|
CWE-362 CWE-415
Race Condition Double Free
|
CVE-2026-32848
|
2026-05-19 03:17 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|