|
201
|
7.5 |
HIGH
Network
|
-
|
-
|
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
New
|
CWE-524
Use of Cache Containing Sensitive Information
|
CVE-2026-48901
|
2026-05-28 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202
|
7.8 |
HIGH
Local
|
-
|
-
|
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker ca…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-48864
|
2026-05-28 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
203
|
- |
|
-
|
-
|
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An atta…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-47161
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
204
|
7.7 |
HIGH
Network
|
-
|
-
|
Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, …
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45715
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
205
|
7.8 |
HIGH
Local
|
-
|
-
|
uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files u…
New
|
CWE-78
OS Command
|
CVE-2026-45152
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
206
|
8.2 |
HIGH
Network
|
-
|
-
|
Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiri…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-45137
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by de…
New
|
CWE-15 CWE-78 CWE-306
External Control of System or Configuration Setting OS Command Missing Authentication for Critical Function
|
CVE-2026-45087
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) directly…
New
|
CWE-94
Code Injection
|
CVE-2026-44888
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. S…
New
|
CWE-94
Code Injection
|
CVE-2026-44887
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210
|
- |
|
-
|
-
|
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL injection. The /pialert/php/server/devi…
New
|
CWE-89
SQL Injection
|
CVE-2026-44886
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|