|
511
|
8.8 |
HIGH
Network
|
-
|
-
|
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attack…
New
|
CWE-22
Path Traversal
|
CVE-2018-25308
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
512
|
6.2 |
MEDIUM
Local
|
-
|
-
|
SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can in…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25313
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
513
|
7.5 |
HIGH
Network
|
-
|
-
|
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence.
Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both hea…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-40560
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
514
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vu…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-23773
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
515
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
New
|
CWE-601
Open Redirect
|
CVE-2026-42525
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
516
|
- |
|
-
|
-
|
Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to tri…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-2810
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
517
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server.
This issue affects all MongoDB Server v8.2 versions, all MongoDB Serv…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-6914
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
518
|
6.3 |
MEDIUM
Network
|
-
|
-
|
An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect h…
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-6915
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
519
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC ad…
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-7422
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
520
|
5.3 |
MEDIUM
Adjacent
|
-
|
-
|
Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing pi…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-7423
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|