|
1751
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and mo…
|
CWE-284
Improper Access Control
|
CVE-2026-49002
|
2026-05-27 18:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1752
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampe…
|
CWE-352
Origin Validation Error
|
CVE-2026-49001
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1753
|
7.0 |
HIGH
Network
|
-
|
-
|
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakag…
|
CWE-310
Cryptographic Issues
|
CVE-2026-49000
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1754
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically lo…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48999
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1755
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Al…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-2255
|
2026-05-27 13:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1756
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notficatio…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-2254
|
2026-05-27 13:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1757
|
7.7 |
HIGH
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.
|
CWE-611
XXE
|
CVE-2026-2253
|
2026-05-27 13:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1758
|
9.8 |
CRITICAL
Network
|
pavel-odintsov
|
fastnetmon
|
FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer,…
|
CWE-787 CWE-122 CWE-193
Out-of-bounds Write Heap-based Buffer Overflow Off-by-one Error
|
CVE-2026-48689
|
2026-05-27 11:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1759
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-8680
|
2026-05-27 08:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1760
|
8.3 |
HIGH
Network
|
-
|
-
|
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44966
|
2026-05-27 07:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|