|
771
|
- |
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-8606
|
2026-05-27 09:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
772
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-8680
|
2026-05-27 08:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
773
|
- |
|
-
|
-
|
Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections.
The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted…
New
|
CWE-93
CRLF Injection
|
CVE-2026-46740
|
2026-05-27 08:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
774
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorit…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-48710
|
2026-05-27 07:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
775
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS c…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-45574
|
2026-05-27 07:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
776
|
- |
|
-
|
-
|
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepti…
New
|
CWE-346
Origin Validation Error
|
CVE-2026-44985
|
2026-05-27 07:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
777
|
8.3 |
HIGH
Network
|
-
|
-
|
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the…
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44966
|
2026-05-27 07:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
778
|
- |
|
-
|
-
|
Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-f…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44903
|
2026-05-27 07:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
779
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-44900
|
2026-05-27 07:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
780
|
7.5 |
HIGH
Network
|
-
|
-
|
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When pr…
New
|
CWE-248
Uncaught Exception
|
CVE-2026-43988
|
2026-05-27 07:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|