|
811
|
9.8 |
CRITICAL
Network
|
-
|
-
|
GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file uploa…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-25332
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
812
|
8.2 |
HIGH
Network
|
-
|
-
|
Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the …
Update
|
CWE-89
SQL Injection
|
CVE-2018-25333
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
813
|
- |
|
-
|
-
|
LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL back…
Update
|
CWE-327 CWE-347
Use of a Broken or Risky Cryptographic Algorithm Improper Verification of Cryptographic Signature
|
CVE-2026-44699
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
814
|
9.1 |
CRITICAL
Network
|
-
|
-
|
OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Core evaluates databas…
Update
|
CWE-94
Code Injection
|
CVE-2026-41258
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
815
|
7.5 |
HIGH
Network
|
-
|
-
|
The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends() contains two fast-path verification bugs for standard P2PKH and native P2WPKH…
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-44714
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
816
|
9.8 |
CRITICAL
Network
|
-
|
-
|
MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitiz…
Update
|
CWE-94
Code Injection
|
CVE-2026-44717
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
817
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle…
Update
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-46383
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
818
|
3.5 |
LOW
Network
|
-
|
-
|
`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users vie…
Update
|
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
|
CVE-2026-45803
|
2026-05-19 04:59 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
819
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hig…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8524
|
2026-05-19 04:43 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
820
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8526
|
2026-05-19 04:43 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|