|
1
|
5.3 |
MEDIUM
Local
|
squirrel-lang
|
squirrel
|
A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results …
New
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-9541
|
2026-05-28 03:48 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
9.8 |
CRITICAL
Network
|
perl
|
perl
|
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of th…
New
|
CWE-680
Integer Overflow to Buffer Overflow
|
CVE-2026-8376
|
2026-05-28 03:43 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
9.1 |
CRITICAL
Network
|
archive\
|
\
|
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() with…
New
|
CWE-59
Link Following
|
CVE-2026-42496
|
2026-05-28 03:37 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
7.5 |
HIGH
Network
|
pavel-odintsov
|
fastnetmon
|
FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains …
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-48688
|
2026-05-28 03:36 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
7.7 |
HIGH
Network
|
microsoft
|
azure_stack_hci
|
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-26147
|
2026-05-28 03:34 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-45659
|
2026-05-28 03:32 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
8.1 |
HIGH
Adjacent
|
pavel-odintsov
|
fastnetmon
|
FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.c…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-48692
|
2026-05-28 03:30 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
4.7 |
MEDIUM
Local
|
nvidia
|
gpu_display_driver
|
NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of…
New
|
CWE-362
Race Condition
|
CVE-2026-24199
|
2026-05-28 03:29 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
9.3 |
CRITICAL
Network
|
microsoft
|
365_copilot
|
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
New
|
CWE-77
Command Injection
|
CVE-2026-41090
|
2026-05-28 03:23 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
7.8 |
HIGH
Local
|
babel
|
babel
|
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel t…
New
|
CWE-94 CWE-843
Code Injection Type Confusion
|
CVE-2026-44728
|
2026-05-28 03:21 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|