|
331
|
- |
|
-
|
-
|
Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the cli…
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2025-68420
|
2026-05-15 01:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
- |
|
-
|
-
|
Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elev…
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2025-68421
|
2026-05-15 01:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
- |
|
-
|
-
|
WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when opened by an authenticated user, results i…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-1630
|
2026-05-15 01:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
- |
|
-
|
-
|
An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on p…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-8295
|
2026-05-15 01:04 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
- |
|
-
|
-
|
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and p…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-21730
|
2026-05-15 01:04 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-35415
|
2026-05-15 00:57 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-35416
|
2026-05-15 00:55 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
New
|
CWE-843
Type Confusion
|
CVE-2026-35417
|
2026-05-15 00:54 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
5.5 |
MEDIUM
Local
|
m2team
|
nanazip
|
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPat…
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-42445
|
2026-05-15 00:54 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
New
|
CWE-367 CWE-416
Time-of-check Time-of-use (TOCTOU) Race Condition Use After Free
|
CVE-2026-35418
|
2026-05-15 00:53 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|