|
531
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-33110
|
2026-05-14 05:53 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
532
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-33112
|
2026-05-14 05:53 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
533
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-35439
|
2026-05-14 05:53 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
534
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-1220
Insufficient Granularity of Access Control
|
CVE-2026-40365
|
2026-05-14 05:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
535
|
8.0 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40368
|
2026-05-14 05:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
536
|
7.5 |
HIGH
Network
|
protobufjs_project
|
protobufjs
|
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected bo…
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-44289
|
2026-05-14 05:50 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
537
|
7.5 |
HIGH
Network
|
protobufjs_project
|
protobufjs
|
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.…
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-45740
|
2026-05-14 05:50 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
538
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40357
|
2026-05-14 05:48 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
539
|
9.6 |
CRITICAL
Network
|
ivanti
|
xtraction
|
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to …
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-8043
|
2026-05-14 05:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
540
|
5.0 |
MEDIUM
Local
|
-
|
-
|
csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-41051
|
2026-05-14 05:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|