|
1111
|
- |
|
-
|
-
|
Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated attacker, giv…
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-44504
|
2026-05-15 03:13 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1112
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.val…
|
CWE-94
Code Injection
|
CVE-2026-42555
|
2026-05-15 03:13 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1113
|
8.8 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
|
CWE-77
Command Injection
|
CVE-2026-44870
|
2026-05-15 03:13 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1114
|
- |
|
-
|
-
|
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, whic…
|
CWE-79
Cross-site Scripting
|
CVE-2026-42159
|
2026-05-15 03:12 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1115
|
- |
|
-
|
-
|
MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42281
|
2026-05-15 03:12 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1116
|
7.7 |
HIGH
Local
|
-
|
-
|
DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore s…
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2026-42283
|
2026-05-15 03:12 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1117
|
9.1 |
CRITICAL
Network
|
n8n-mcp
|
n8n-mcp
|
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before version 2.50.2, there is an authenticated server-side …
|
CWE-367 CWE-918
Time-of-check Time-of-use (TOCTOU) Race Condition Server-Side Request Forgery (SSRF)
|
CVE-2026-44694
|
2026-05-15 03:10 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1118
|
4.3 |
MEDIUM
Network
|
n8n-mcp
|
n8n-mcp
|
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MC…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-42282
|
2026-05-15 03:07 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1119
|
7.5 |
HIGH
Network
|
russh_project warpgate_project
|
russh warpgate
|
Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authentication handler. A malici…
|
CWE-770 CWE-789
Allocation of Resources Without Limits or Throttling Memory Allocation with Excessive Size Value
|
CVE-2026-42189
|
2026-05-15 03:07 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1120
|
5.3 |
MEDIUM
Network
|
n8n-mcp
|
n8n-mcp
|
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n-mcp runs in HTTP transport mode, incoming request…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-41495
|
2026-05-15 03:06 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|