|
211
|
7.8 |
HIGH
Local
|
openimageio
|
openimageio
|
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a heap-based buffer overflow in the H…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-43906
|
2026-05-16 04:42 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212
|
4.9 |
MEDIUM
Network
|
argoproj
|
argo_workflows
|
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the workflow executor logs all artifact re…
Update
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-42295
|
2026-05-16 04:40 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213
|
8.1 |
HIGH
Network
|
argoproj
|
argo_workflows
|
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass …
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-42296
|
2026-05-16 04:39 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214
|
6.1 |
MEDIUM
Network
|
microsoft
|
exchange_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42897
|
2026-05-16 04:35 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215
|
8.3 |
HIGH
Network
|
argoproj
|
argo_workflows
|
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provid…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-42297
|
2026-05-16 04:26 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216
|
7.5 |
HIGH
Network
|
getarcane
|
arcane
|
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Huma backend are registered without…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-42461
|
2026-05-16 04:18 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.
To remediate this issue, users s…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8686
|
2026-05-16 04:17 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG fi…
New
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-4054
|
2026-05-16 04:17 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219
|
3.1 |
LOW
Network
|
-
|
-
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, a…
New
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2026-4053
|
2026-05-16 04:17 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220
|
8.1 |
HIGH
Network
|
-
|
-
|
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator t…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-46407
|
2026-05-16 04:17 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|