|
581
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-60889
|
2026-05-1 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
582
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
New
|
-
|
CVE-2025-51850
|
2026-05-1 01:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
583
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
New
|
-
|
CVE-2025-51849
|
2026-05-1 01:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
584
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
New
|
-
|
CVE-2025-51847
|
2026-05-1 01:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
585
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12494. Reason: This candidate is a reservation duplicate of CVE-2025-12494. Notes: All CVE users should reference …
New
|
-
|
CVE-2025-13890
|
2026-05-1 01:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
586
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served t…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-33467
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
587
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both…
New
|
CWE-798 CWE-912
Use of Hard-coded Credentials Hidden Functionality
|
CVE-2026-41446
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
588
|
7.2 |
HIGH
Network
|
-
|
-
|
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42615
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
589
|
- |
|
-
|
-
|
SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The vulnerability arises from inadequate validation and…
New
|
CWE-89
SQL Injection
|
CVE-2026-3325
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
590
|
- |
|
-
|
-
|
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unco…
New
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2026-42248
|
2026-05-1 00:48 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|