|
201
|
8.3 |
HIGH
Network
|
-
|
-
|
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.
New
|
CWE-93
CRLF Injection
|
CVE-2026-32993
|
2026-05-15 01:49 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202
|
7.5 |
HIGH
Network
|
-
|
-
|
hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingComplete…
New
|
CWE-284 CWE-287
Improper Access Control Improper Authentication
|
CVE-2026-44478
|
2026-05-15 01:49 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
203
|
8.1 |
HIGH
Network
|
-
|
-
|
Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.
New
|
CWE-89
SQL Injection
|
CVE-2026-29206
|
2026-05-15 01:49 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
204
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-32991
|
2026-05-15 01:49 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
205
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify commun…
New
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-41281
|
2026-05-15 01:49 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
206
|
7.1 |
HIGH
Network
|
-
|
-
|
SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.
New
|
CWE-89
SQL Injection
|
CVE-2026-46445
|
2026-05-15 01:49 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207
|
7.1 |
HIGH
Network
|
-
|
-
|
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
New
|
CWE-89
SQL Injection
|
CVE-2026-46446
|
2026-05-15 01:49 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208
|
- |
|
-
|
-
|
Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the user, control the Archon UI features, and steal all …
New
|
-
|
CVE-2025-69443
|
2026-05-15 01:49 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209
|
- |
|
-
|
-
|
Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitizat…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5790
|
2026-05-15 01:46 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210
|
- |
|
-
|
-
|
Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated at…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-5798
|
2026-05-15 01:46 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|