|
641
|
4.3 |
MEDIUM
Network
|
hcltech
|
bigfix_webui_api bigfix_webui_application_administration bigfix_webui_cmep bigfix_webui_common bigfix_webui_content_app bigfix_webui_custom bigfix_webui_data_sync bigfix_webui_ex…
|
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized…
Update
|
CWE-862
Missing Authorization
|
CVE-2025-15634
|
2026-05-15 05:28 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
642
|
7.8 |
HIGH
Local
|
python
|
pillow
|
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code e…
Update
|
CWE-190 CWE-787
Integer Overflow or Wraparound Out-of-bounds Write
|
CVE-2026-42311
|
2026-05-15 05:27 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
643
|
7.6 |
HIGH
Network
|
-
|
-
|
Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted…
New
|
CWE-22
Path Traversal
|
CVE-2026-45225
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
644
|
3.3 |
LOW
Local
|
-
|
-
|
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handler's Open method re…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-42444
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
645
|
8.2 |
HIGH
Network
|
-
|
-
|
Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not r…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42260
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
646
|
7.3 |
HIGH
Network
|
-
|
-
|
An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-37430
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
647
|
7.5 |
HIGH
Network
|
-
|
-
|
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expos…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-31240
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
648
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method u…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31239
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
649
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads mo…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31238
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
650
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework auto…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31237
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|