|
101
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-bas…
New
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-8212
|
2026-05-10 08:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this issue is the function update of the file org/codelibs/fess/app/web/admin/design/AdminDesignAction.java of the component JS…
New
|
CWE-74 CWE-94
Injection Code Injection
|
CVE-2026-8211
|
2026-05-10 08:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
2.2 |
LOW
Local
|
-
|
-
|
GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let syste…
New
|
CWE-441
Confused Deputy
|
CVE-2026-45182
|
2026-05-10 08:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Update of the file helper.go of the component Update H…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-8210
|
2026-05-10 06:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
3.7 |
LOW
Network
|
-
|
-
|
A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginControlle…
New
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-8196
|
2026-05-10 06:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/C…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-8195
|
2026-05-10 05:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argu…
New
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-8194
|
2026-05-10 05:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
8.1 |
HIGH
Network
|
-
|
-
|
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with…
New
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-42606
|
2026-05-10 05:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
8.8 |
HIGH
Network
|
-
|
-
|
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}…
New
|
CWE-22
Path Traversal
|
CVE-2026-42605
|
2026-05-10 05:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
- |
|
-
|
-
|
ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the craw…
New
|
CWE-88
Argument Injection
|
CVE-2026-42601
|
2026-05-10 05:16 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|