|
661
|
- |
|
-
|
-
|
Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivilege…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-32603
|
2026-05-7 01:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
662
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-28780
|
2026-05-7 01:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
663
|
8.1 |
HIGH
Network
|
redis
|
redis
|
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-aft…
New
|
CWE-416
Use After Free
|
CVE-2026-23631
|
2026-05-7 01:14 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
664
|
8.8 |
HIGH
Network
|
redis
|
redis
|
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blo…
New
|
CWE-416
Use After Free
|
CVE-2026-23479
|
2026-05-7 00:53 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
665
|
7.5 |
HIGH
Network
|
-
|
-
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through…
New
|
CWE-200
Information Exposure
|
CVE-2026-43646
|
2026-05-7 00:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
666
|
- |
|
-
|
-
|
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulner…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-41287
|
2026-05-7 00:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
667
|
3.7 |
LOW
Network
|
-
|
-
|
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-sit…
New
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2025-31983
|
2026-05-7 00:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
668
|
3.7 |
LOW
Network
|
-
|
-
|
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of s…
New
|
CWE-200
Information Exposure
|
CVE-2025-31982
|
2026-05-7 00:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
669
|
6.1 |
MEDIUM
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowi…
New
|
CWE-601
Open Redirect
|
CVE-2026-42230
|
2026-05-6 23:57 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
670
|
8.8 |
HIGH
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be…
New
|
CWE-89
SQL Injection
|
CVE-2026-42229
|
2026-05-6 23:56 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|