|
241
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr…
New
|
CWE-601
Open Redirect
|
CVE-2026-42207
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to execute arbitrary Python code provided by the user,…
Update
|
CWE-94
Code Injection
|
CVE-2026-31231
|
2026-05-16 04:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
8.8 |
HIGH
Network
|
snorkel
|
snorkel
|
The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler mo…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31223
|
2026-05-16 04:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
8.8 |
HIGH
Network
|
snorkel
|
snorkel
|
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.lo…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31222
|
2026-05-16 04:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
8.8 |
HIGH
Network
|
lightningai
|
pytorch_lightning
|
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which …
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31221
|
2026-05-16 04:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
9.8 |
CRITICAL
Network
|
-
|
-
|
PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. The system allows low-privileged…
Update
|
CWE-94
Code Injection
|
CVE-2026-31220
|
2026-05-16 04:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset.
New
|
CWE-284
Improper Access Control
|
CVE-2025-67437
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_des…
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47968
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
6.1 |
MEDIUM
Network
|
-
|
-
|
PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers …
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47967
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
8.2 |
HIGH
Network
|
-
|
-
|
PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database conte…
New
|
CWE-89
SQL Injection
|
CVE-2021-47966
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|