|
7301
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
HID: appletb-kbd: run inactivity autodim from workqueues
The autodim code in hid-appletb-kbd takes backlight_device->ops_lock
via…
|
-
|
CVE-2026-46202
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7302
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: fix empty payload in tap skb for non-linear buffers
For non-linear skbs, virtio_transport_build_skb() goes through
…
|
-
|
CVE-2026-46207
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7303
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata()
msm_ioctl_gem_info_get_metadata() always returns 0 regardles…
|
-
|
CVE-2026-46211
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7304
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
spi: fsl: fix controller deregistration
Make sure to deregister the controller before releasing underlying
resources like DMA dur…
|
-
|
CVE-2026-46226
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7305
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
spi: ch341: fix devres lifetime
USB drivers bind to USB interfaces and any device managed resources
should have their lifetime ti…
|
-
|
CVE-2026-46228
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7306
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
KFD VRAM allocations set AMDGPU_GEM_CREATE_VRAM_WIPE_ON_RELEA…
|
-
|
CVE-2026-46229
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7307
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: i2c: ov5647: Fix runtime PM refcount leak in s_ctrl
Three control cases (AUTOGAIN, EXPOSURE_AUTO, ANALOGUE_GAIN) directly
…
|
-
|
CVE-2026-46239
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7308
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
HID: appletb-kbd: fix UAF in inactivity-timer cleanup path
Commit 38224c472a03 ("HID: appletb-kbd: fix slab use-after-free bug in…
|
-
|
CVE-2026-46213
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7309
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: rockchip: rkcif: Add missing MUST_CONNECT flag to pads
The pads missed checks for connected devices which may a null deref…
|
-
|
CVE-2026-46222
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7310
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure
When drm_gpuvm_resv_object_alloc() fails, the pre-allocated st…
|
-
|
CVE-2026-46224
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7311
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
spi: mpc52xx: fix use-after-free on registration failure
Make sure to disable and free the interrupts in case controller
registra…
|
-
|
CVE-2026-46241
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7312
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
cgroup: Defer css percpu_ref kill on rmdir until cgroup is depopulated
A chain of commits going back to v7.0 reworked rmdir to sa…
|
-
|
CVE-2026-46223
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7313
|
6.1 |
MEDIUM
Network
|
mistune_project
|
mistune
|
Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options direc…
|
CWE-79
Cross-site Scripting
|
CVE-2026-44896
|
2026-05-28 22:43 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7314
|
6.1 |
MEDIUM
Network
|
mistune_project
|
mistune
|
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value directly into the HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2026-44897
|
2026-05-28 22:42 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7315
|
6.1 |
MEDIUM
Network
|
mistune_project
|
mistune
|
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, text) tuples. Both the id value (used a…
|
CWE-79
Cross-site Scripting
|
CVE-2026-44898
|
2026-05-28 22:42 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7316
|
5.4 |
MEDIUM
Network
|
apache
|
shiro
|
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.
In affected versions, insufficient validation of this client-controlled value coul…
|
CWE-601
Open Redirect
|
CVE-2026-48589
|
2026-05-28 22:38 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7317
|
6.1 |
MEDIUM
Network
|
mistune_project
|
mistune
|
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^…
|
CWE-79
Cross-site Scripting
|
CVE-2026-44899
|
2026-05-28 22:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7318
|
8.8 |
HIGH
Network
|
tanium
|
connect
|
Tanium addressed an unauthorized code execution vulnerability in Connect.
|
CWE-78
OS Command
|
CVE-2026-9207
|
2026-05-28 22:31 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7319
|
10.0 |
CRITICAL
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authorization. A network a…
|
CWE-863
Incorrect Authorization
|
CVE-2026-44330
|
2026-05-28 22:06 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7320
|
9.9 |
CRITICAL
Network
|
-
|
-
|
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation whe…
|
CWE-59
Link Following
|
CVE-2026-7374
|
2026-05-28 12:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7321
|
7.2 |
HIGH
Network
|
apache
|
syncope
|
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted c…
|
CWE-653
Improper Isolation or Compartmentalization
|
CVE-2026-42782
|
2026-05-28 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7322
|
2.4 |
LOW
Physics
|
-
|
-
|
AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an ove…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-68711
|
2026-05-28 06:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7323
|
2.4 |
LOW
Physics
|
-
|
-
|
Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay …
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-68710
|
2026-05-28 06:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7324
|
2.4 |
LOW
Physics
|
-
|
-
|
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's …
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-68708
|
2026-05-28 06:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7325
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authen…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-1402
|
2026-05-28 05:53 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7326
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authentic…
|
CWE-862
Missing Authorization
|
CVE-2026-2601
|
2026-05-28 05:53 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7327
|
8.2 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authent…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-4868
|
2026-05-28 05:47 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7328
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level,…
|
CWE-862
Missing Authorization
|
CVE-2026-5296
|
2026-05-28 05:46 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7329
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauth…
|
CWE-863
Incorrect Authorization
|
CVE-2026-6713
|
2026-05-28 05:46 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7330
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authen…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2026-8716
|
2026-05-28 05:45 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7331
|
6.3 |
MEDIUM
Network
|
-
|
-
|
FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability exists in FacturaScripts' product image upload func…
|
CWE-94 CWE-434
Code Injection Unrestricted Upload of File with Dangerous Type
|
CVE-2026-42879
|
2026-05-28 04:49 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7332
|
- |
-
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch (chat/api/o…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42335
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7333
|
- |
-
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsi…
|
CWE-367 CWE-918
Time-of-check Time-of-use (TOCTOU) Race Condition Server-Side Request Forgery (SSRF)
|
CVE-2026-42336
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7334
|
- |
-
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The en…
|
CWE-862
Missing Authorization
|
CVE-2026-42337
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7335
|
7.5 |
HIGH
Network
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth clas…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-44847
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7336
|
- |
-
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are fetc…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45412
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7337
|
- |
-
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow tables or GPU-accelerated brute f…
|
CWE-328
Use of Weak Hash
|
CVE-2026-45413
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7338
|
7.4 |
HIGH
Network
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI netwo…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-45575
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7339
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any patient's electronic he…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-47672
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7340
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-44900
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7341
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS c…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-45574
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7342
|
- |
-
|
-
|
-
|
Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution.
The handle_event("save-job", ...) handler in 'El…
|
CWE-862
Missing Authorization
|
CVE-2026-48592
|
2026-05-28 04:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7343
|
- |
-
|
-
|
-
|
Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory exhaustion via unbounded cron range expansion.
An attacker with access to sched…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-48593
|
2026-05-28 04:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7344
|
5.9 |
MEDIUM
Network
|
putty
|
putty
|
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
|
CWE-415
Double Free
|
CVE-2026-48850
|
2026-05-28 04:14 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7345
|
3.1 |
LOW
Network
|
putty
|
putty
|
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-48851
|
2026-05-28 04:12 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7346
|
3.7 |
LOW
Network
|
putty
|
putty
|
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
|
CWE-617
Reachable Assertion
|
CVE-2026-48852
|
2026-05-28 04:11 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7347
|
5.3 |
MEDIUM
Local
|
squirrel-lang
|
squirrel
|
A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results …
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-9541
|
2026-05-28 03:48 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7348
|
9.8 |
CRITICAL
Network
|
perl
|
perl
|
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of th…
|
CWE-680
Integer Overflow to Buffer Overflow
|
CVE-2026-8376
|
2026-05-28 03:43 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7349
|
7.5 |
HIGH
Network
|
pavel-odintsov
|
fastnetmon
|
FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-48688
|
2026-05-28 03:36 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7350
|
7.7 |
HIGH
Network
|
microsoft
|
azure_stack_hci
|
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
|
CWE-20
Improper Input Validation
|
CVE-2026-26147
|
2026-05-28 03:34 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|