|
581
|
8.1 |
HIGH
Network
|
-
|
-
|
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.…
New
|
CWE-1004
Sensitive Cookie Without 'HttpOnly' Flag
|
CVE-2026-42239
|
2026-05-8 05:35 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
582
|
- |
|
-
|
-
|
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
New
|
-
|
CVE-2026-42499
|
2026-05-8 05:33 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
583
|
7.6 |
HIGH
Network
|
-
|
-
|
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. F…
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-43510
|
2026-05-8 05:32 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
584
|
3.3 |
LOW
Local
|
-
|
-
|
A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation can lead to out-of-bo…
New
|
CWE-119 CWE-125
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Read
|
CVE-2026-8088
|
2026-05-8 05:32 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
585
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldNam…
New
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-8087
|
2026-05-8 05:32 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
586
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready().
syzbot reported use-after-free of AF_UNIX soc…
Update
|
CWE-416
Use After Free
|
CVE-2026-43016
|
2026-05-8 05:31 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
587
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: macb: fix clk handling on PCI glue driver removal
platform_device_unregister() may still want to use the registered clks
dur…
Update
|
CWE-416
Use After Free
|
CVE-2026-43015
|
2026-05-8 05:31 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
588
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: macb: properly unregister fixed rate clocks
The additional resources allocated with clk_register_fixed_rate() need
to be rel…
Update
|
NVD-CWE-noinfo
|
CVE-2026-43014
|
2026-05-8 05:29 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
589
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: lag: Check for LAG device before creating debugfs
__mlx5_lag_dev_add_mdev() may return 0 (success) even when an error
o…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-43013
|
2026-05-8 05:28 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
590
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix switchdev mode rollback in case of failure
If for some internal reason switchdev mode fails, we rollback to legacy
…
Update
|
NVD-CWE-noinfo
|
CVE-2026-43012
|
2026-05-8 05:28 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|