|
91
|
8.8 |
HIGH
Network
|
-
|
-
|
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-78 CWE-384
OS Command Session Fixation
|
CVE-2026-41613
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
New
|
CWE-22 CWE-23
Path Traversal Relative Path Traversal
|
CVE-2026-41612
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
New
|
CWE-77 CWE-80
Command Injection Basic XSS
|
CVE-2026-41611
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
6.3 |
MEDIUM
Local
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
New
|
CWE-59 CWE-79 CWE-200
Link Following Cross-site Scripting Information Exposure
|
CVE-2026-41610
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
- |
|
-
|
-
|
Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted app…
New
|
CWE-601
Open Redirect
|
CVE-2026-41513
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
- |
|
-
|
-
|
Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-41293
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
- |
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 t…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-41284
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-41250
|
2026-05-13 03:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature ove…
New
|
CWE-74
Injection
|
CVE-2026-41109
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
7.4 |
HIGH
Network
|
-
|
-
|
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-41107
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|