|
481
|
7.3 |
HIGH
Network
|
-
|
-
|
Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section permits users to mention other users; however, the backend does not validate or san…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-43887
|
2026-05-13 00:13 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
482
|
7.7 |
HIGH
Network
|
-
|
-
|
Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API endpoint in server/routes/api/subscriptions/subscriptions.ts exhibits a broken aut…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-43890
|
2026-05-13 00:13 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
483
|
5.3 |
MEDIUM
Network
|
uriparser_project
|
uriparser
|
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
Update
|
CWE-197
Numeric Truncation Error
|
CVE-2026-44927
|
2026-05-13 00:12 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
484
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could a…
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-7255
|
2026-05-13 00:11 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
485
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operat…
New
|
CWE-78
OS Command
|
CVE-2026-7256
|
2026-05-13 00:11 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
486
|
4.4 |
MEDIUM
Local
|
-
|
-
|
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker …
New
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2026-7257
|
2026-05-13 00:11 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
487
|
7.5 |
HIGH
Network
|
-
|
-
|
** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-7287
|
2026-05-13 00:11 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
488
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, aseHttpRequestHan…
Update
|
CWE-22
Path Traversal
|
CVE-2026-38360
|
2026-05-13 00:10 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
489
|
7.4 |
HIGH
Local
|
-
|
-
|
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directo…
Update
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-34354
|
2026-05-13 00:10 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
490
|
7.2 |
HIGH
Network
|
-
|
-
|
Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.
New
|
CWE-22
Path Traversal
|
CVE-2026-41951
|
2026-05-13 00:10 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|