|
681
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) b…
Update
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-42583
|
2026-05-18 21:22 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
682
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer …
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42587
|
2026-05-18 21:20 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
683
|
9.4 |
CRITICAL
Network
|
thecodingmachine
|
gotenberg
|
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is r…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42596
|
2026-05-18 21:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
684
|
3.7 |
LOW
Network
|
-
|
-
|
A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation cau…
New
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2026-8803
|
2026-05-18 21:16 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
685
|
- |
|
-
|
-
|
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash
New
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-0983
|
2026-05-18 21:16 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
686
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limi…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-44248
|
2026-05-18 21:15 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
687
|
8.2 |
HIGH
Network
|
thecodingmachine
|
gotenberg
|
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary…
Update
|
CWE-184
Incomplete Blacklist
|
CVE-2026-42590
|
2026-05-18 21:15 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
688
|
9.1 |
CRITICAL
Network
|
netty
|
netty
|
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() onc…
Update
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-42584
|
2026-05-18 21:15 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
689
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argumen…
New
|
CWE-22
Path Traversal
|
CVE-2026-8802
|
2026-05-18 20:16 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
690
|
- |
|
-
|
-
|
Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-4320
|
2026-05-18 20:16 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|