|
1221
|
8.7 |
HIGH
Network
|
-
|
-
|
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification …
|
CWE-79
Cross-site Scripting
|
CVE-2026-44667
|
2026-05-28 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1222
|
8.2 |
HIGH
Network
|
-
|
-
|
RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming …
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44483
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1223
|
6.1 |
MEDIUM
Adjacent
|
-
|
-
|
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored va…
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2026-44475
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1224
|
3.7 |
LOW
Adjacent
|
-
|
-
|
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 §6.9.5.1 — it could se…
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2026-44474
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1225
|
7.1 |
HIGH
Adjacent
|
-
|
-
|
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does…
|
CWE-358 CWE-863
Improperly Implemented Security Check for Standard Incorrect Authorization
|
CVE-2026-44473
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1226
|
- |
|
-
|
-
|
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verific…
|
CWE-295 CWE-297
Improper Certificate Validation Improper Validation of Certificate with Host Mismatch
|
CVE-2026-42790
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1227
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.
|
-
|
CVE-2026-38931
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1228
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via …
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-12686
|
2026-05-28 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1229
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Account Manager for WooCom…
|
CWE-862
Missing Authorization
|
CVE-2022-41656
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1230
|
7.5 |
HIGH
Network
|
ibm
|
http_server
|
IBM HTTP Server 8.5, and 9.0
|
CWE-94
Code Injection
|
CVE-2026-9170
|
2026-05-28 02:07 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|