|
811
|
4.9 |
MEDIUM
Network
|
-
|
-
|
A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Succe…
New
|
CWE-284
Improper Access Control
|
CVE-2026-44874
|
2026-05-14 01:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
812
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated wh…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-44873
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
813
|
7.2 |
HIGH
Network
|
-
|
-
|
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
New
|
CWE-77
Command Injection
|
CVE-2026-44866
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
814
|
8.1 |
HIGH
Network
|
-
|
-
|
ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDele…
New
|
CWE-352 CWE-650
Origin Validation Error Trusting HTTP Permission Methods on the Server Side
|
CVE-2026-44548
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
815
|
9.6 |
CRITICAL
Network
|
-
|
-
|
ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/publ…
New
|
CWE-287 CWE-304
Improper Authentication Missing Critical Step in Authentication
|
CVE-2026-44547
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
816
|
- |
|
-
|
-
|
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Broken Access Control allows reading of sketch logs f…
New
|
CWE-284
Improper Access Control
|
CVE-2026-44352
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
817
|
8.1 |
HIGH
Network
|
-
|
-
|
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk en…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-44260
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
818
|
4.6 |
MEDIUM
Network
|
-
|
-
|
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security heade…
New
|
CWE-80
Basic XSS
|
CVE-2026-44259
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
819
|
3.7 |
LOW
Network
|
-
|
-
|
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where th…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-44242
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
820
|
7.5 |
HIGH
Network
|
-
|
-
|
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, TimeConverterRegistrar caches DateTimeForma…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-44241
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|