|
91
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The device is con…
New
|
CWE-285
Improper Authorization
|
CVE-2026-30495
|
2026-05-9 08:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-67202
|
2026-05-9 08:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
9.8 |
CRITICAL
Network
|
-
|
-
|
NPM package next-npm-version1.0.1 is vulnerable to Command injection.
New
|
CWE-94
Code Injection
|
CVE-2025-63706
|
2026-05-9 08:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
9.8 |
CRITICAL
Network
|
-
|
-
|
npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2025-63703
|
2026-05-9 08:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
7.5 |
HIGH
Network
|
-
|
-
|
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
New
|
-
|
CVE-2026-42499
|
2026-05-9 07:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
- |
|
-
|
-
|
Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially…
New
|
CWE-89
SQL Injection
|
CVE-2026-42287
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
- |
|
-
|
-
|
Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing un…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-42286
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
8.8 |
HIGH
Network
|
-
|
-
|
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by …
New
|
CWE-78
OS Command
|
CVE-2026-42215
|
2026-05-9 07:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
- |
|
-
|
-
|
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, the inc "filename" directive in GPPL postprocessor f…
New
|
CWE-22 CWE-200 CWE-295 CWE-918
Path Traversal Information Exposure Improper Certificate Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-42213
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
- |
|
-
|
-
|
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor ID…
New
|
CWE-400 CWE-611 CWE-776
Uncontrolled Resource Consumption XXE XML Entity Expansion
|
CVE-2026-42212
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|