|
521
|
- |
|
-
|
-
|
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load(…
New
|
-
|
CVE-2026-31252
|
2026-05-13 00:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
522
|
- |
|
-
|
-
|
The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechani…
New
|
-
|
CVE-2026-31253
|
2026-05-13 00:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
523
|
- |
|
-
|
-
|
The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python …
New
|
-
|
CVE-2026-31254
|
2026-05-13 00:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
524
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-36906
|
2026-05-13 00:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
525
|
- |
|
-
|
-
|
SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution…
New
|
-
|
CVE-2026-36962
|
2026-05-13 00:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
526
|
8.1 |
HIGH
Network
|
-
|
-
|
HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve …
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-38568
|
2026-05-13 00:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
527
|
5.4 |
MEDIUM
Network
|
-
|
-
|
HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add or POST /feedback/add.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-38569
|
2026-05-13 00:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
528
|
5.3 |
MEDIUM
Network
|
uriparser_project
|
uriparser
|
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
Update
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2026-44928
|
2026-05-13 00:00 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
529
|
5.3 |
MEDIUM
Network
|
sync-in
|
sync-in_server
|
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthen…
Update
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-41161
|
2026-05-13 00:00 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
530
|
5.3 |
MEDIUM
Network
|
angular
|
angular
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Se…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41423
|
2026-05-12 23:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|