|
221
|
- |
|
-
|
-
|
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller…
New
|
CWE-89
SQL Injection
|
CVE-2026-42208
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222
|
5.3 |
MEDIUM
Network
|
-
|
-
|
novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intend…
New
|
CWE-22
Path Traversal
|
CVE-2026-42028
|
2026-05-9 03:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-67886
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224
|
7.3 |
HIGH
Network
|
-
|
-
|
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
New
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2025-55449
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225
|
7.3 |
HIGH
Network
|
-
|
-
|
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.
New
|
CWE-94
Code Injection
|
CVE-2024-46507
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
226
|
7.3 |
HIGH
Network
|
-
|
-
|
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in free…
New
|
CWE-77
Command Injection
|
CVE-2024-45257
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
227
|
6.3 |
MEDIUM
Network
|
-
|
-
|
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
New
|
CWE-89
SQL Injection
|
CVE-2024-33722
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
228
|
7.3 |
HIGH
Network
|
-
|
-
|
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.
New
|
CWE-89
SQL Injection
|
CVE-2024-33288
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
229
|
5.3 |
MEDIUM
Local
|
-
|
-
|
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.
New
|
CWE-77
Command Injection
|
CVE-2023-47268
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
230
|
- |
|
-
|
-
|
Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not ex…
New
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2013-10075
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|