|
481
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the …
New
|
CWE-22 CWE-284
Path Traversal Improper Access Control
|
CVE-2026-44225
|
2026-05-14 22:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
482
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role)…
New
|
CWE-20 CWE-89
Improper Input Validation SQL Injection
|
CVE-2026-44204
|
2026-05-14 22:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
483
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI respo…
New
|
CWE-248 CWE-755
Uncaught Exception Improper Handling of Exceptional Conditions
|
CVE-2026-42545
|
2026-05-14 22:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
484
|
8.8 |
HIGH
Network
|
-
|
-
|
ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token valid…
New
|
CWE-269 CWE-306 CWE-352
Improper Privilege Management Missing Authentication for Critical Function Origin Validation Error
|
CVE-2026-42289
|
2026-05-14 22:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
485
|
- |
|
-
|
-
|
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, c…
New
|
CWE-284
Improper Access Control
|
CVE-2026-42158
|
2026-05-14 22:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
486
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected (hidden/debug mode).
New
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-36742
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
487
|
7.2 |
HIGH
Network
|
-
|
-
|
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. A…
New
|
CWE-77
Command Injection
|
CVE-2026-36741
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
488
|
7.5 |
HIGH
Network
|
-
|
-
|
striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-28344
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
489
|
7.5 |
HIGH
Network
|
-
|
-
|
striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-28343
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
490
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_SmartAudio::loop, AP_SmartAudio…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2024-51395
|
2026-05-14 22:16 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|