|
1391
|
7.5 |
HIGH
Network
|
dell
|
unisphere_for_powermax_virtual_appliance
|
Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp
|
CWE-285
Improper Authorization
|
CVE-2022-34363
|
2026-05-30 00:53 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1392
|
6.5 |
MEDIUM
Network
|
golang
|
net
|
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-25680
|
2026-05-30 00:47 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1393
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sendi…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-44213
|
2026-05-30 00:42 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1394
|
7.1 |
HIGH
Network
|
-
|
-
|
Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token…
|
CWE-863
Incorrect Authorization
|
CVE-2026-42280
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1395
|
7.5 |
HIGH
Network
|
-
|
-
|
opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics en…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2026-44902
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1396
|
- |
|
-
|
-
|
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit o…
|
CWE-180 CWE-345
Incorrect Behavior Order: Validate Before Canonicalize Insufficient Verification of Data Authenticity
|
CVE-2026-45022
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1397
|
- |
|
-
|
-
|
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in …
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-45570
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1398
|
5.4 |
MEDIUM
Network
|
-
|
-
|
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside…
|
CWE-22
Path Traversal
|
CVE-2026-45571
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1399
|
- |
|
-
|
-
|
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. Howev…
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-9739
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1400
|
5.3 |
MEDIUM
Network
|
-
|
-
|
opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggag…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-45292
|
2026-05-30 00:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|