|
401
|
7.5 |
HIGH
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS…
New
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-43654
|
2026-05-14 23:32 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
402
|
6.5 |
MEDIUM
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS …
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-28847
|
2026-05-14 23:32 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
403
|
6.5 |
MEDIUM
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously c…
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-28902
|
2026-05-14 23:32 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
404
|
6.5 |
MEDIUM
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS …
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-28903
|
2026-05-14 23:32 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
405
|
8.1 |
HIGH
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS…
New
|
CWE-20 CWE-116
Improper Input Validation Improper Encoding or Escaping of Output
|
CVE-2026-28907
|
2026-05-14 23:32 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
406
|
6.5 |
MEDIUM
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processin…
New
|
CWE-416
Use After Free
|
CVE-2026-28942
|
2026-05-14 23:32 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
407
|
9.9 |
CRITICAL
Network
|
microsoft
|
dynamics_365
|
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
New
|
CWE-94
Code Injection
|
CVE-2026-42898
|
2026-05-14 23:31 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
408
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2025
|
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
New
|
CWE-122 CWE-190
Heap-based Buffer Overflow Integer Overflow or Wraparound
|
CVE-2026-42896
|
2026-05-14 23:31 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
409
|
7.5 |
HIGH
Network
|
microsoft
|
copilot_chat
|
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
Update
|
CWE-77
Command Injection
|
CVE-2026-33111
|
2026-05-14 23:31 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
410
|
8.8 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
New
|
CWE-77
Command Injection
|
CVE-2026-44871
|
2026-05-14 23:29 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|