|
641
|
- |
|
-
|
-
|
Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remo…
New
|
-
|
CVE-2026-39292
|
2026-05-30 00:39 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
642
|
9.1 |
CRITICAL
Network
|
-
|
-
|
The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. Th…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4290
|
2026-05-30 00:39 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
643
|
8.8 |
HIGH
Network
|
-
|
-
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 in…
Update
|
CWE-78
OS Command
|
CVE-2026-44345
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
644
|
8.8 |
HIGH
Network
|
-
|
-
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injected value in envs[*].n…
Update
|
CWE-78 CWE-94
OS Command Code Injection
|
CVE-2026-44346
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
645
|
8.2 |
HIGH
Network
|
-
|
-
|
Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiri…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-45137
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
646
|
6.8 |
MEDIUM
Adjacent
|
-
|
-
|
Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluste…
New
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-44247
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
647
|
- |
|
-
|
-
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
New
|
CWE-94 CWE-732 CWE-940
Code Injection Incorrect Permission Assignment for Critical Resource Improper Verification of Source of a Communication Channel
|
CVE-2026-45353
|
2026-05-30 00:34 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
648
|
- |
|
-
|
-
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…
New
|
CWE-326 CWE-329 CWE-353 CWE-759 CWE-916
Inadequate Encryption Strength Not Using a Random IV with CBC Mode Missing Support for Integrity Check Use of a One-Way Hash without a Salt Use of Password Hash With Insufficient Computational Effort
|
CVE-2026-45787
|
2026-05-30 00:34 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
649
|
6.1 |
MEDIUM
Network
|
golang
|
net
|
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…
Update
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-25681
|
2026-05-30 00:30 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
650
|
7.5 |
HIGH
Network
|
-
|
-
|
Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass use…
Update
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-44209
|
2026-05-30 00:29 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|