|
341
|
- |
|
-
|
-
|
Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Improper Validation.
This vulnerability is associated wi…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-47074
|
2026-05-30 00:29 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342
|
6.1 |
MEDIUM
Network
|
golang
|
net
|
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…
New
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-27136
|
2026-05-30 00:27 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343
|
9.6 |
CRITICAL
Network
|
golang
|
net
|
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com…
New
|
CWE-1289
Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-39821
|
2026-05-30 00:26 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C…
New
|
CWE-416
Use After Free
|
CVE-2026-9970
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown function of the file /myprofile.php. Such manipulation of the argument ID leads to …
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9416
|
2026-05-30 00:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346
|
4.8 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This v…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-6324
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-veh…
New
|
CWE-307 CWE-400 CWE-770
mproper Restriction of Excessive Authentication Attempts Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-49324
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348
|
4.3 |
MEDIUM
Physics
|
-
|
-
|
Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with…
New
|
CWE-327 CWE-798 CWE-1390
Use of a Broken or Risky Cryptographic Algorithm Use of Hard-coded Credentials Weak Authentication
|
CVE-2026-49323
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349
|
4.3 |
MEDIUM
Physics
|
-
|
-
|
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to…
New
|
CWE-294 CWE-327 CWE-1390
Authentication Bypass by Capture-replay Use of a Broken or Risky Cryptographic Algorithm Weak Authentication
|
CVE-2026-49322
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350
|
- |
|
-
|
-
|
WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST pa…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-47696
|
2026-05-30 00:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|