|
461
|
- |
|
-
|
-
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
New
|
CWE-78
OS Command
|
CVE-2025-41276
|
2026-05-29 23:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
462
|
- |
|
-
|
-
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…
New
|
CWE-78
OS Command
|
CVE-2025-41277
|
2026-05-29 23:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
463
|
- |
|
-
|
-
|
Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Ho…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2025-41278
|
2026-05-29 23:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
464
|
5.4 |
MEDIUM
Network
|
networktocode
|
nautobot
|
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to referen…
New
|
CWE-862
Missing Authorization
|
CVE-2026-44794
|
2026-05-29 22:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
465
|
6.5 |
MEDIUM
Network
|
networktocode
|
nautobot
|
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to a…
New
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-44796
|
2026-05-29 22:27 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
466
|
8.5 |
HIGH
Network
|
networktocode
|
nautobot
|
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-44797
|
2026-05-29 22:26 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
467
|
- |
|
-
|
-
|
Rejected reason: Further research determined the issue is not a vulnerability.
New
|
-
|
CVE-2026-45611
|
2026-05-29 22:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
468
|
9.9 |
CRITICAL
Network
|
-
|
-
|
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated u…
New
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-45312
|
2026-05-29 22:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
469
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in all versions up to, and …
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-14042
|
2026-05-29 22:09 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
470
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet conte…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7430
|
2026-05-29 22:09 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|