|
111
|
5.3 |
MEDIUM
Network
|
-
|
-
|
opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggag…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-45292
|
2026-05-29 02:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
112
|
- |
|
-
|
-
|
GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop application. An a…
New
|
CWE-94
Code Injection
|
CVE-2026-45261
|
2026-05-29 02:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
113
|
7.5 |
HIGH
Network
|
-
|
-
|
opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics en…
New
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2026-44902
|
2026-05-29 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
114
|
7.5 |
HIGH
Network
|
-
|
-
|
esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in…
New
|
CWE-22
Path Traversal
|
CVE-2026-44594
|
2026-05-29 02:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
115
|
8.7 |
HIGH
Network
|
-
|
-
|
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in …
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-44543
|
2026-05-29 02:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
116
|
- |
|
-
|
-
|
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as t…
New
|
CWE-250 CWE-271 CWE-426
Execution with Unnecessary Privileges Privilege Dropping / Lowering Errors Untrusted Search Path
|
CVE-2026-44477
|
2026-05-29 02:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
117
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the …
New
|
CWE-89
SQL Injection
|
CVE-2026-38930
|
2026-05-29 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
118
|
7.3 |
HIGH
Network
|
-
|
-
|
An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.
New
|
CWE-94
Code Injection
|
CVE-2026-37713
|
2026-05-29 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
119
|
7.3 |
HIGH
Network
|
-
|
-
|
An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in fun…
New
|
CWE-94
Code Injection
|
CVE-2026-37712
|
2026-05-29 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
120
|
8.0 |
HIGH
Network
|
-
|
-
|
An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component
New
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-37266
|
2026-05-29 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|