|
601
|
- |
|
-
|
-
|
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in …
Update
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-45570
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
602
|
5.4 |
MEDIUM
Network
|
-
|
-
|
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside…
Update
|
CWE-22
Path Traversal
|
CVE-2026-45571
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
603
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across…
Update
|
CWE-384
Session Fixation
|
CVE-2026-48545
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
604
|
8.0 |
HIGH
Network
|
-
|
-
|
Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federat…
Update
|
CWE-22
Path Traversal
|
CVE-2026-6957
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
605
|
5.5 |
MEDIUM
Local
|
-
|
-
|
ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9759
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
606
|
- |
|
-
|
-
|
claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directl…
Update
|
CWE-78 CWE-94
OS Command Code Injection
|
CVE-2026-45136
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
607
|
- |
|
-
|
-
|
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. Howev…
Update
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-9739
|
2026-05-30 00:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
608
|
5.3 |
MEDIUM
Network
|
-
|
-
|
opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggag…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-45292
|
2026-05-30 00:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
609
|
6.0 |
MEDIUM
Network
|
-
|
-
|
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-42999
|
2026-05-30 00:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
610
|
6.0 |
MEDIUM
Network
|
-
|
-
|
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to ad…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-43000
|
2026-05-30 00:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|