|
321
|
- |
|
-
|
-
|
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component …
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-8326
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
322
|
- |
|
-
|
-
|
Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path w…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-9508
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
323
|
- |
|
-
|
-
|
An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST reques…
New
|
CWE-248
Uncaught Exception
|
CVE-2026-9509
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
324
|
- |
|
-
|
-
|
Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remo…
New
|
-
|
CVE-2026-39292
|
2026-05-30 00:39 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
325
|
9.1 |
CRITICAL
Network
|
-
|
-
|
The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. Th…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4290
|
2026-05-30 00:39 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
326
|
8.8 |
HIGH
Network
|
-
|
-
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 in…
New
|
CWE-78
OS Command
|
CVE-2026-44345
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
327
|
8.8 |
HIGH
Network
|
-
|
-
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injected value in envs[*].n…
New
|
CWE-78 CWE-94
OS Command Code Injection
|
CVE-2026-44346
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
328
|
6.8 |
MEDIUM
Adjacent
|
-
|
-
|
Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluste…
New
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-44247
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
329
|
8.2 |
HIGH
Network
|
-
|
-
|
Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiri…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-45137
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
330
|
- |
|
-
|
-
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
New
|
CWE-94 CWE-732 CWE-940
Code Injection Incorrect Permission Assignment for Critical Resource Improper Verification of Source of a Communication Channel
|
CVE-2026-45353
|
2026-05-30 00:34 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|