|
461
|
6.5 |
MEDIUM
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe …
New
|
CWE-200
Information Exposure
|
CVE-2026-28920
|
2026-05-14 23:01 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
462
|
7.5 |
HIGH
Network
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.
New
|
CWE-284
Improper Access Control
|
CVE-2026-28930
|
2026-05-14 23:01 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
463
|
7.5 |
HIGH
Network
|
apple
|
ipados iphone_os macos visionos
|
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. Processing a malicio…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-28936
|
2026-05-14 23:01 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
464
|
4.6 |
MEDIUM
Physics
|
apple
|
macos
|
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-28961
|
2026-05-14 23:01 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
465
|
6.2 |
MEDIUM
Local
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 2…
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-28977
|
2026-05-14 23:01 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
466
|
5.3 |
MEDIUM
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick…
Update
|
CWE-78
OS Command
|
CVE-2026-44656
|
2026-05-14 22:59 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
467
|
5.3 |
MEDIUM
Network
|
python
|
urllib3
|
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fa…
New
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2026-44431
|
2026-05-14 22:56 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
468
|
4.4 |
MEDIUM
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a cr…
Update
|
CWE-78
OS Command
|
CVE-2026-42307
|
2026-05-14 22:55 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
469
|
5.3 |
MEDIUM
Network
|
redwoodjs
|
redwoodsdk
|
RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforcement but no origin validation. A request originating…
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-42190
|
2026-05-14 22:54 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
470
|
7.2 |
HIGH
Network
|
claris
|
filemaker_cloud
|
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operat…
New
|
CWE-94
Code Injection
|
CVE-2026-43680
|
2026-05-14 22:53 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|