|
151
|
- |
|
-
|
-
|
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted reposi…
New
|
CWE-426
Untrusted Search Path
|
CVE-2026-45772
|
2026-05-19 02:34 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
152
|
- |
|
-
|
-
|
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the l…
New
|
CWE-352 CWE-384
Origin Validation Error Session Fixation
|
CVE-2026-45773
|
2026-05-19 02:34 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
153
|
- |
|
-
|
-
|
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-contr…
New
|
CWE-77
Command Injection
|
CVE-2026-46508
|
2026-05-19 02:34 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
154
|
6.5 |
MEDIUM
Network
|
dovecot open-xchange
|
dovecot
|
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to deg…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40016
|
2026-05-19 02:34 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
155
|
8.2 |
HIGH
Network
|
-
|
-
|
PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database conte…
New
|
CWE-89
SQL Injection
|
CVE-2021-47966
|
2026-05-19 02:33 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
156
|
6.1 |
MEDIUM
Network
|
-
|
-
|
PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers …
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47967
|
2026-05-19 02:33 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
157
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-28759
|
2026-05-19 02:32 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
158
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cau…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-2325
|
2026-05-19 02:32 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
159
|
3.8 |
LOW
Network
|
-
|
-
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-3495
|
2026-05-19 02:32 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
160
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with re…
New
|
CWE-862
Missing Authorization
|
CVE-2026-3637
|
2026-05-19 02:32 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|