|
1001
|
8.8 |
HIGH
Network
|
-
|
-
|
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious…
|
CWE-89
SQL Injection
|
CVE-2026-44447
|
2026-05-15 01:29 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1002
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Hermes WebUI prior to 0.51.44 - Release T contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary files by importing a crafted ses…
|
CWE-22
Path Traversal
|
CVE-2026-22677
|
2026-05-15 01:24 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1003
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without…
|
CWE-79
Cross-site Scripting
|
CVE-2026-45228
|
2026-05-15 01:24 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1004
|
8.8 |
HIGH
Network
|
-
|
-
|
Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui…
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-45229
|
2026-05-15 01:24 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1005
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies raw POST username values into the display_name fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2026-41932
|
2026-05-15 01:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1006
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking pro…
|
CWE-548
Exposure of Information Through Directory Listing
|
CVE-2026-41933
|
2026-05-15 01:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1007
|
7.1 |
HIGH
Network
|
-
|
-
|
Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base::init() repeatedly invokes permission() on error handlers, causing infinite rec…
|
CWE-209 CWE-674
Information Exposure Through an Error Message Uncontrolled Recursion
|
CVE-2026-41935
|
2026-05-15 01:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1008
|
7.2 |
HIGH
Network
|
-
|
-
|
Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP f…
|
CWE-61 CWE-434
UNIX Symbolic Link (Symlink) Following Unrestricted Upload of File with Dangerous Type
|
CVE-2026-41937
|
2026-05-15 01:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1009
|
- |
|
-
|
-
|
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-0235
|
2026-05-15 01:21 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1010
|
- |
|
-
|
-
|
A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverag…
|
CWE-94
Code Injection
|
CVE-2026-0236
|
2026-05-15 01:21 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|