|
181
|
- |
|
-
|
-
|
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or mo…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-44379
|
2026-05-15 01:57 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
182
|
- |
|
-
|
-
|
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organ…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-44380
|
2026-05-15 01:57 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
183
|
- |
|
-
|
-
|
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow …
New
|
CWE-89
SQL Injection
|
CVE-2026-44381
|
2026-05-15 01:57 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
184
|
- |
|
-
|
-
|
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
New
|
CWE-506
Embedded Malicious Code
|
CVE-2026-44484
|
2026-05-15 01:57 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
185
|
- |
|
-
|
-
|
MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The h…
New
|
CWE-295 CWE-918
Improper Certificate Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-44363
|
2026-05-15 01:54 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
186
|
- |
|
-
|
-
|
MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker …
New
|
CWE-352
Origin Validation Error
|
CVE-2026-44364
|
2026-05-15 01:54 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
187
|
- |
|
-
|
-
|
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query parameter directly into an application/javascript response body without validating tha…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42548
|
2026-05-15 01:51 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
188
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recursive: true) on a path built from the user-supplied controller name, before Nett…
New
|
CWE-22
Path Traversal
|
CVE-2026-42549
|
2026-05-15 01:51 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
189
|
8.8 |
HIGH
Network
|
-
|
-
|
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() build SQL statements by concatenating the $table argument and the k…
New
|
CWE-89
SQL Injection
|
CVE-2026-42550
|
2026-05-15 01:51 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190
|
7.5 |
HIGH
Network
|
-
|
-
|
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP-Method-Override header and the $_REQUEST['_method'] parameter on any HTTP verb…
New
|
CWE-436
Interpretation Conflict
|
CVE-2026-42551
|
2026-05-15 01:51 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|