|
81
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless of the caller's O…
New
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-46431
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
82
|
7.5 |
HIGH
Network
|
-
|
-
|
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibl…
New
|
CWE-209 CWE-489 CWE-540 CWE-1188
Information Exposure Through an Error Message Exposure of Data Element to Wrong Session Inclusion of Sensitive Information in Source Code Insecure Default Initialization of Resource
|
CVE-2026-45728
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
83
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent…
New
|
CWE-20 CWE-426 CWE-552
Improper Input Validation Untrusted Search Path Files or Directories Accessible to External Parties
|
CVE-2026-45721
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
84
|
- |
|
-
|
-
|
Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level authorization. A low-privileged user who knows or gues…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44776
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
85
|
- |
|
-
|
-
|
Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to page images from an…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-44775
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
86
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leadi…
New
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-44749
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
87
|
7.2 |
HIGH
Network
|
-
|
-
|
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a user from a differ…
New
|
CWE-284
Improper Access Control
|
CVE-2026-44730
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
88
|
8.2 |
HIGH
Local
|
-
|
-
|
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel t…
New
|
CWE-94 CWE-843
Code Injection Type Confusion
|
CVE-2026-44728
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
89
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enf…
New
|
CWE-283 CWE-287
Unverified Ownership Improper Authentication
|
CVE-2026-44707
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
90
|
8.5 |
HIGH
Network
|
-
|
-
|
Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type da…
New
|
CWE-89
SQL Injection
|
CVE-2026-44706
|
2026-05-27 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|