|
271
|
8.7 |
HIGH
Network
|
protobufjs_project
|
protobufjs-cli
|
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When ge…
Update
|
CWE-94
Code Injection
|
CVE-2026-44295
|
2026-05-20 05:37 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
7.2 |
HIGH
Network
|
dkfz
|
nnu-net
|
nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable…
Update
|
CWE-74
Injection
|
CVE-2026-44246
|
2026-05-20 05:10 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
6.1 |
MEDIUM
Network
|
beaugunderson
|
ip-address
|
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-42338
|
2026-05-20 05:04 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
8.8 |
HIGH
Network
|
tabby
|
tabby
|
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supp…
Update
|
CWE-78
OS Command
|
CVE-2026-45035
|
2026-05-20 04:41 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: …
Update
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8567
|
2026-05-20 04:28 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
7.1 |
HIGH
Network
|
tabby
|
tabby
|
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without …
Update
|
CWE-184 CWE-601
Incomplete Blacklist Open Redirect
|
CVE-2026-45037
|
2026-05-20 04:27 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity:…
Update
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8573
|
2026-05-20 04:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM…
Update
|
CWE-416
Use After Free
|
CVE-2026-8574
|
2026-05-20 04:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
9.4 |
CRITICAL
Network
|
dify
|
dify
|
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficie…
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-41948
|
2026-05-20 04:25 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
9.1 |
CRITICAL
Network
|
dify
|
dify
|
Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant own…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41947
|
2026-05-20 04:24 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|