|
1081
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
New
|
CWE-77 CWE-80
Command Injection Basic XSS
|
CVE-2026-41611
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1082
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
New
|
CWE-22 CWE-23
Path Traversal Relative Path Traversal
|
CVE-2026-41612
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1083
|
8.8 |
HIGH
Network
|
-
|
-
|
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-78 CWE-384
OS Command Session Fixation
|
CVE-2026-41613
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1084
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-42831
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1085
|
7.7 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-42832
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1086
|
- |
|
-
|
-
|
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3.
New
|
-
|
CVE-2026-8401
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1087
|
7.2 |
HIGH
Network
|
-
|
-
|
An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.
This issue affe…
New
|
CWE-77
Command Injection
|
CVE-2026-8431
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1088
|
8.8 |
HIGH
Network
|
-
|
-
|
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issu…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8053
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1089
|
2.7 |
LOW
Network
|
-
|
-
|
When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted.
This is…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-8200
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1090
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilizatio…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-8202
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|