|
911
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argume…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9446
|
2026-05-29 03:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
8.1 |
HIGH
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immedia…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2026-9095
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to validate post-login redirect targets applied urlj…
|
CWE-601
Open Redirect
|
CVE-2026-45307
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
- |
|
-
|
-
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync…
|
CWE-94 CWE-345 CWE-494 CWE-915
Code Injection Insufficient Verification of Data Authenticity Download of Code Without Integrity Check Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-45058
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
- |
|
-
|
-
|
bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corru…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-42250
|
2026-05-29 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
7.8 |
HIGH
Local
|
-
|
-
|
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration …
|
CWE-77
Command Injection
|
CVE-2026-40034
|
2026-05-29 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
4.2 |
MEDIUM
Network
|
-
|
-
|
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registe…
|
CWE-441 CWE-918
Confused Deputy Server-Side Request Forgery (SSRF)
|
CVE-2026-48522
|
2026-05-29 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
7.4 |
HIGH
Network
|
-
|
-
|
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate…
|
CWE-287 CWE-347
Improper Authentication Improper Verification of Cryptographic Signature
|
CVE-2026-48526
|
2026-05-29 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
5.4 |
MEDIUM
Network
|
-
|
-
|
PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-48523
|
2026-05-29 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
3.7 |
LOW
Network
|
-
|
-
|
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no ra…
|
CWE-460 CWE-755
Improper Cleanup on Thrown Exception Improper Handling of Exceptional Conditions
|
CVE-2026-48524
|
2026-05-29 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|