|
1441
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-45083
|
2026-05-30 00:29 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1442
|
- |
|
-
|
-
|
Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Improper Validation.
This vulnerability is associated wi…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-47074
|
2026-05-30 00:29 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1443
|
6.1 |
MEDIUM
Network
|
golang
|
net
|
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-27136
|
2026-05-30 00:27 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1444
|
9.6 |
CRITICAL
Network
|
golang
|
net
|
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com…
|
CWE-1289
Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-39821
|
2026-05-30 00:26 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1445
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown function of the file /myprofile.php. Such manipulation of the argument ID leads to …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9416
|
2026-05-30 00:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1446
|
4.8 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This v…
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-6324
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1447
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-veh…
|
CWE-307 CWE-400 CWE-770
mproper Restriction of Excessive Authentication Attempts Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-49324
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1448
|
4.3 |
MEDIUM
Physics
|
-
|
-
|
Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with…
|
CWE-327 CWE-798 CWE-1390
Use of a Broken or Risky Cryptographic Algorithm Use of Hard-coded Credentials Weak Authentication
|
CVE-2026-49323
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1449
|
4.3 |
MEDIUM
Physics
|
-
|
-
|
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to…
|
CWE-294 CWE-327 CWE-1390
Authentication Bypass by Capture-replay Use of a Broken or Risky Cryptographic Algorithm Weak Authentication
|
CVE-2026-49322
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1450
|
- |
|
-
|
-
|
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses i…
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-45041
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|