|
31
|
7.3 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ctnetlink: ignore explicit helper on new expectations
Use the existing master conntrack helper, anything else is not r…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-43025
|
2026-05-9 03:17 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
- |
|
-
|
-
|
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.
The built-in rand function is predictable, and unsuitable for cryptography.
New
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2026-6659
|
2026-05-9 03:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
- |
|
-
|
-
|
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller…
New
|
CWE-89
SQL Injection
|
CVE-2026-42208
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
5.3 |
MEDIUM
Network
|
-
|
-
|
novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intend…
New
|
CWE-22
Path Traversal
|
CVE-2026-42028
|
2026-05-9 03:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants.
This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0.
The Proxm…
New
|
CWE-200
Information Exposure
|
CVE-2026-25199
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an…
New
|
CWE-94
Code Injection
|
CVE-2026-25077
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-67886
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
7.3 |
HIGH
Network
|
-
|
-
|
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
New
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2025-55449
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
7.3 |
HIGH
Network
|
-
|
-
|
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.
New
|
CWE-94
Code Injection
|
CVE-2024-46507
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
7.3 |
HIGH
Network
|
-
|
-
|
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in free…
New
|
CWE-77
Command Injection
|
CVE-2024-45257
|
2026-05-9 03:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|