|
7401
|
8.1 |
HIGH
Network
|
pavel-odintsov
|
fastnetmon
|
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php…
|
CWE-78
OS Command
|
CVE-2026-48695
|
2026-05-28 00:51 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7402
|
6.2 |
MEDIUM
Local
|
pavel-odintsov
|
fastnetmon
|
FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.
|
CWE-120 CWE-676
Classic Buffer Overflow Use of Potentially Dangerous Function
|
CVE-2026-48696
|
2026-05-28 00:42 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7403
|
7.2 |
HIGH
Network
|
ibm
|
engineering_lifecycle_management
|
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2026-4051
|
2026-05-28 00:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7404
|
7.2 |
HIGH
Network
|
citeum
|
opencti
|
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a user from a differ…
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-44730
|
2026-05-28 00:40 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7405
|
7.4 |
HIGH
Network
|
pavel-odintsov
|
fastnetmon
|
FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-48697
|
2026-05-28 00:31 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7406
|
5.3 |
MEDIUM
Network
|
apache
|
apache-airflow-providers-fab
|
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache…
|
CWE-90
LDAP Injection
|
CVE-2026-46745
|
2026-05-28 00:31 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7407
|
9.8 |
CRITICAL
Network
|
pavel-odintsov
|
fastnetmon
|
FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attr…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-48691
|
2026-05-28 00:29 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7408
|
6.5 |
MEDIUM
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS.…
|
CWE-125 CWE-476
Out-of-bounds Read NULL Pointer Dereference
|
CVE-2026-41069
|
2026-05-28 00:26 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7409
|
8.1 |
HIGH
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chun…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-41071
|
2026-05-28 00:25 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7410
|
- |
-
|
-
|
-
|
When creating an export through the pretix API, API clients are
returned an UUID value for their export job (a long, random string like
35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the A…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-9712
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7411
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument u…
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-9579
|
2026-05-28 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7412
|
- |
-
|
-
|
-
|
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
|
CWE-24
Path Traversal: '../filedir'
|
CVE-2026-49103
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7413
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).
|
CWE-79
Cross-site Scripting
|
CVE-2026-49102
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7414
|
4.7 |
MEDIUM
Network
|
-
|
-
|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing.
This issue affects Facebook for WooCommerce: from n/a through 3.7.0.
|
CWE-601
Open Redirect
|
CVE-2026-49059
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7415
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects ElementsKit Elementor addon…
|
CWE-862
Missing Authorization
|
CVE-2026-49053
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7416
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects ElementsKit Elementor addon…
|
CWE-862
Missing Authorization
|
CVE-2026-49052
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7417
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WP Meta and Date Remover: …
|
CWE-862
Missing Authorization
|
CVE-2026-49051
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7418
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects DearFlip: from n/a through 2.4.27.
|
CWE-862
Missing Authorization
|
CVE-2026-49047
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7419
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blind SQL Injection.
This issue affects Duplicate Pa…
|
CWE-89
SQL Injection
|
CVE-2026-49046
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7420
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Adminimize: from n/a through 1.11.11.
|
CWE-862
Missing Authorization
|
CVE-2026-49045
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7421
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS.
This issue affects Ad…
|
CWE-79
Cross-site Scripting
|
CVE-2026-49044
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7422
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects SVG Support: from n/a through 2.5.14.
|
CWE-862
Missing Authorization
|
CVE-2026-48973
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7423
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the im…
|
CWE-79
Cross-site Scripting
|
CVE-2026-47119
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7424
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image file serving endpoint, whi…
|
CWE-22
Path Traversal
|
CVE-2026-47118
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7425
|
9.8 |
CRITICAL
Network
|
-
|
-
|
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-44668
|
2026-05-28 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7426
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety sca…
|
CWE-78
OS Command
|
CVE-2026-44444
|
2026-05-28 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7427
|
- |
-
|
-
|
-
|
An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actions_addupdatedelete.inc.php
|
-
|
CVE-2026-37711
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7428
|
- |
-
|
-
|
-
|
Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).
|
-
|
CVE-2026-31266
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7429
|
- |
-
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.
|
-
|
CVE-2026-30498
|
2026-05-28 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7430
|
2.7 |
LOW
Network
|
gtranslate
|
gtranslate
|
Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing.
This issue affects Translate Drupal with GTranslate: from 0.…
|
CWE-471
Modification of Assumed-Immutable Data (MAID)
|
CVE-2026-8492
|
2026-05-28 00:15 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7431
|
9.8 |
CRITICAL
Network
|
date_ical_project
|
date_ical
|
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.
This issue affects Date iCal: from 0.0.0 before 4.0.15.
|
CWE-862
Missing Authorization
|
CVE-2026-8495
|
2026-05-28 00:14 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7432
|
5.4 |
MEDIUM
Network
|
colorbox_inline_project
|
colorbox_inline
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS).
This issue affects Colorbox Inline: fr…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8493
|
2026-05-28 00:08 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7433
|
3.7 |
LOW
Network
|
adcisolutions
|
node_view_permissions
|
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing.
This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-8491
|
2026-05-28 00:00 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7434
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory …
|
CWE-88
Argument Injection
|
CVE-2026-44449
|
2026-05-27 23:57 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7435
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the …
|
CWE-88
Argument Injection
|
CVE-2026-44450
|
2026-05-27 23:57 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7436
|
7.1 |
HIGH
Network
|
-
|
-
|
The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, al…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6268
|
2026-05-27 23:55 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7437
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8676
|
2026-05-27 23:54 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7438
|
5.8 |
MEDIUM
Local
|
-
|
-
|
When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']['result']['compile_…
|
CWE-22
Path Traversal
|
CVE-2026-41009
|
2026-05-27 23:54 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7439
|
5.0 |
MEDIUM
Local
|
-
|
-
|
AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response['value']['result']['compile_log_id'] (line 332-338…
|
CWE-284
Improper Access Control
|
CVE-2026-41704
|
2026-05-27 23:54 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7440
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log…
|
CWE-521
Weak Password Requirements
|
CVE-2024-40684
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7441
|
7.2 |
HIGH
Network
|
-
|
-
|
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating syste…
|
CWE-530
Exposure of Backup File to an Unauthorized Control Sphere
|
CVE-2024-56462
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7442
|
5.1 |
MEDIUM
Local
|
-
|
-
|
IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied M…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-2607
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7443
|
9.8 |
CRITICAL
Network
|
-
|
-
|
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affecte…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8175
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7444
|
8.8 |
HIGH
Network
|
-
|
-
|
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affecte…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-8179
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7445
|
7.5 |
HIGH
Network
|
-
|
-
|
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affecte…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-8180
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7446
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affecte…
|
CWE-22
Path Traversal
|
CVE-2026-9035
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7447
|
8.8 |
HIGH
Network
|
-
|
-
|
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2025-41669
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7448
|
7.8 |
HIGH
Local
|
-
|
-
|
A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2025-41670
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7449
|
7.5 |
HIGH
Network
|
-
|
-
|
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This…
|
CWE-89
SQL Injection
|
CVE-2026-40810
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7450
|
7.5 |
HIGH
Network
|
-
|
-
|
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralization of special elements in a SQL SELECT command. Thi…
|
CWE-89
SQL Injection
|
CVE-2026-40811
|
2026-05-27 23:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|