|
1
|
7.5 |
HIGH
Network
|
apache
|
tomcat
|
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 t…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-41284
|
2026-05-15 03:59 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
7.8 |
HIGH
Local
|
lightningai
|
pytorch_lightning
|
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which …
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31221
|
2026-05-15 03:54 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
7.3 |
HIGH
Network
|
mozilla
|
firefox
|
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
New
|
CWE-416
Use After Free
|
CVE-2026-8390
|
2026-05-15 03:53 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
7.5 |
HIGH
Network
|
pgbouncer
|
pgbouncer
|
An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malforme…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-6664
|
2026-05-15 03:52 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
9.8 |
CRITICAL
Network
|
pgbouncer
|
pgbouncer
|
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM se…
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-6665
|
2026-05-15 03:52 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
7.3 |
HIGH
Network
|
apache
|
tomcat
|
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1…
New
|
CWE-200
Information Exposure
|
CVE-2026-42498
|
2026-05-15 03:51 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
3.5 |
LOW
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control o…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7471
|
2026-05-15 03:50 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7481
|
2026-05-15 03:50 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with projec…
New
|
CWE-862
Missing Authorization
|
CVE-2026-8144
|
2026-05-15 03:50 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause den…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-8280
|
2026-05-15 03:50 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|